Probabilistic Data Structures Vulnerability Affects Redis Servers
CVE-2024-25116
5.5MEDIUM
What is CVE-2024-25116?
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the CF.RESERVE command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
Affected Version(s)
RedisBloom >= 2.0.0, < 2.4.7 < 2.0.0, 2.4.7
RedisBloom >= 2.5.0, < 2.6.10 < 2.5.0, 2.6.10
