#VU102383 Use-after-free in Redis - CVE-2024-46981
Published: January 6, 2025 / Updated: March 21, 2025
Redis
Redis Labs
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when handling Lua script commands. A remote user can pass a specially crafted Lua script to the application and execute arbitrary code on the system..
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.