Impact
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Affected Systems
The flaw affects Redis, including both the open-source Redis distribution and Redis Software Enterprise releases. Versions prior to 6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1 are vulnerable. All releases in the 6.x, 7.x, and 8.x series before those patch levels are at risk.
Risk and Exploitability
With a CVSS score of 7.5 this vulnerability is considered high. Because the attack does not require authentication and can be launched from any network location that can reach the server's TLS port, the likelihood of exploitation in the wild is low, with an EPSS score of < 1% indicating a very low exploitation probability. The vulnerability is not currently included in the CISA KEV list, but the lack of KEV status does not reduce the risk to administrators.
OpenCVE Enrichment