Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-15047

clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of…

Technology

Redis

CVSS Score

9.8 / 10.0

Affected Versions

4.0.2

Upstream Fix

See upstream advisory

Published

October 6, 2017

OSSeva Coverage

Fixed upstream

Description

The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."

Is your Redis deployment affected?

If you're running 4.0.2, you need this patch. Book a discovery call to get covered.