CVE-2022-0543

CVE Published 2022-02-18
Related CWE(s) CWE-862: Missing Authorization
Related Vendor(s) redis
Related Product(s) redis
Exploitation Reported (CISA KEV) 2022-03-28
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References