Probabilistic Data Structures Vulnerability Affects Redis Servers
CVE-2024-25116

5.5MEDIUM

Key Information:

Vendor

Redisbloom

Vendor
CVE Published:
9 April 2024

What is CVE-2024-25116?

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the CF.RESERVE command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.

Affected Version(s)

RedisBloom >= 2.0.0, < 2.4.7 < 2.0.0, 2.4.7

RedisBloom >= 2.5.0, < 2.6.10 < 2.5.0, 2.6.10

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.