Code Injection in Redis - CVE-2022-24735
Published: April 29, 2022
Vulnerability identifier: #VU62693
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24735
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the Lua script execution environment. A remote user can send a specially crafted request and execute arbitrary code on the target system with elevated privileges.
Affected software
Redis
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
openEuler
Fedora
Oracle Communications Operations Monitor
IBM Planning Analytics Workspace
QRadar Assistant
redis
redis-debuginfo
redis-debugsource
redis6
redis6-doc
redis6-debuginfo
redis6-devel
redis6-debugsource
redis (Red Hat package)
dev-db/redis
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
openEuler
Fedora
Oracle Communications Operations Monitor
IBM Planning Analytics Workspace
QRadar Assistant
redis
redis-debuginfo
redis-debugsource
redis6
redis6-doc
redis6-debuginfo
redis6-devel
redis6-debugsource
redis (Red Hat package)
dev-db/redis
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
How to mitigate CVE-2022-24735
Install updates from vendor's website.
Redis - addressed in versions 6.2.7, 7.0.0
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Assistant - update to 3.8.1
redis - update to 6.0.14-150200.6.11.1
redis-debuginfo - update to 6.0.14-150200.6.11.1
redis-debugsource - update to 6.0.14-150200.6.11.1
redis6 - update to 6.2.7-1
redis6-doc - update to 6.2.7-1
redis6 - update to 6.2.7-1
redis6-debuginfo - update to 6.2.7-1
redis6-devel - update to 6.2.7-1
redis6-debugsource - update to 6.2.7-1
redis (Red Hat package) - update to 6.2.7-1.el9
redis - addressed in versions 6.2.7-1.fc34, 6.2.7-1.fc35, 6.2.7-1.fc36
dev-db/redis - update to 7.0.5
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.3
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.3
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Assistant - update to 3.8.1
redis - update to 6.0.14-150200.6.11.1
redis-debuginfo - update to 6.0.14-150200.6.11.1
redis-debugsource - update to 6.0.14-150200.6.11.1
redis6 - update to 6.2.7-1
redis6-doc - update to 6.2.7-1
redis6 - update to 6.2.7-1
redis6-debuginfo - update to 6.2.7-1
redis6-devel - update to 6.2.7-1
redis6-debugsource - update to 6.2.7-1
redis (Red Hat package) - update to 6.2.7-1.el9
redis - addressed in versions 6.2.7-1.fc34, 6.2.7-1.fc35, 6.2.7-1.fc36
dev-db/redis - update to 7.0.5
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.3
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Redis
- SUSE update for redis
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Gentoo update for Redis
- Red Hat Enterprise Linux 8 update for the redis:6 module
- Red Hat Enterprise Linux 9 update for redis
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift
- SUSE update for redis
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- openEuler update for redis6
- Amazon Linux AMI update for redis6
- Multiple vulnerabilities in IBM QRadar Assistant
- Fedora 34 update for redis
- Fedora 35 update for redis
- Fedora 36 update for redis
- openEuler update for redis