Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2017-15047
clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of…
Technology
Redis
CVSS Score
9.8 / 10.0
Affected Versions
4.0.2
Upstream Fix
See upstream advisory
Published
October 6, 2017
OSSeva Coverage
Fixed upstream
Description
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."
Is your Redis deployment affected?
If you're running 4.0.2, you need this patch. Book a discovery call to get covered.