MEDIUM · 5.3

CVE-2021-32672

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond th...

Vulnerability Description

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedisRedis>= 3.2.0, < 5.0.14
RedhatSoftware Collections-
RedhatEnterprise Linux8.0
DebianDebian Linux10.0
FedoraprojectFedora33
NetappManagement Services For Element Software-
NetappManagement Services For Netapp Hci-
OracleCommunications Operations Monitor4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-32672?

CVE-2021-32672 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond th...

How severe is CVE-2021-32672?

CVE-2021-32672 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-32672?

Check the references section above for vendor advisories and patch information. Affected products include: Redis Redis, Redhat Software Collections, Redhat Enterprise Linux, Debian Debian Linux, Fedoraproject Fedora.