Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
CVE-2023-36824
What is CVE-2023-36824?
An identified vulnerability in Redis versions prior to 7.0.12 involves a heap overflow that can occur when key names are extracted from commands with varying arguments. This flaw may lead to heap corruption and allows for reading arbitrary memory, potentially enabling authenticated users to execute specially crafted commands such as COMMAND GETKEYS or COMMAND GETKEYSANDFLAGS. This represents a critical risk as attackers could leverage these commands in environments where ACL rules have been configured to align with key names.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
redis >= 7.0.0, < 7.0.12
References
EPSS Score
90% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
