CVE-2022-0543
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
- Affected products
- Astra Linux, Debian-Specific Redis Server, Linuxmint, Redis, Ubuntu
- Redis
- All versions
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 99.3% (100th percentile)
- Weakness
- CWE-862
- NVD status
- Analyzed
- Published
- 2022-02-18
CVE-2022-0543 at NVD
10 known exploits for CVE-2022-0543
Proof-of-concept code and exploit modules indexed by Sploitus
Redis-RCE-x-HTB
exploit-library
cve-poc-collection
Exploit for Missing Authorization in Redis
Exploit for Missing Authorization in Redis
Redis Lua Sandbox Escape Exploit
Redis Lua Sandbox Escape
Exploit for Missing Authorization in Redis
Exploit for Missing Authorization in Redis
Redis Lua Sandbox Escape