Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2024-46981
Redis Lua script can manipulate the garbage collector and lead to remote code execution
Technology
Redis
CVSS Score
9.8 / 10.0
Affected Versions
All versions with Lua scripting before 6.2.17, 7.2.7 and 7.4.2
Upstream Fix
6.2.17, 7.2.7, 7.4.2
Published
January 6, 2025
OSSeva Coverage
Fixed upstream
Description
An authenticated user can send a crafted Lua script that manipulates the garbage collector and may lead to remote code execution. The advisory lists every Redis version as affected. Restricting EVAL and EVALSHA with ACLs mitigates it on servers that cannot be upgraded.
Is your Redis deployment affected?
If you're running All versions with Lua scripting before 6.2.17, 7.2.7 and 7.4.2, you need this patch. Book a discovery call to get covered.