#VU72634 Resource exhaustion in Redis - CVE-2022-36021
Published: February 28, 2023 / Updated: March 1, 2023
Redis
Redis Labs
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when matching commands (like SCAN or KEYS) with a specially crafted pattern. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.