Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2024-46981

Redis Lua script can manipulate the garbage collector and lead to remote code execution

Technology

Redis

CVSS Score

9.8 / 10.0

Affected Versions

All versions with Lua scripting before 6.2.17, 7.2.7 and 7.4.2

Upstream Fix

6.2.17, 7.2.7, 7.4.2

Published

January 6, 2025

OSSeva Coverage

Fixed upstream

Description

An authenticated user can send a crafted Lua script that manipulates the garbage collector and may lead to remote code execution. The advisory lists every Redis version as affected. Restricting EVAL and EVALSHA with ACLs mitigates it on servers that cannot be upgraded.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running All versions with Lua scripting before 6.2.17, 7.2.7 and 7.4.2, you need this patch. Book a discovery call to get covered.