Description
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
Published: 2024-04-09
Score: 7 High
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-22475 RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-01T23:36:21.630Z

Reserved: 2024-02-05T14:14:46.379Z

Link: CVE-2024-25115

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.630Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-09T18:15:08.850

Modified: 2024-11-21T09:00:17.090

Link: CVE-2024-25115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses