Settings

Theme

Redis Critical Remote Execution Vulnerability: CVE‑2025‑49844

redis.io

1 points by sciencejerk 3 months ago · 3 comments

Reader

sciencejerkOP 3 months ago

A 13‑year Redis flaw (CVE‑2025‑49844) allows attackers to escape Lua sandbox and run code on hosts, if they are authenticated and Lua Script uploads are permitted.

Fixed releases: 7.22.2-12 and above, 7.8.6-207 and above, 7.4.6-272 and above, 7.2.4-138 and above, 6.4.2-131 and above

Exploit appears to be available, so patch quickly! https://redrays.io/blog/poc-for-cve-2025-49844-cve-2025-4681...

ChrisArchitect 3 months ago

[dupe] Discussion: https://news.ycombinator.com/item?id=45497027

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection