CVE-2021-31294
published 2023-07-15CVE-2021-31294: Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command)…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.31%
67.7th percentile
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | redis | < redis 5:7.0.1-4 (bookworm) | redis 5:7.0.1-4 (bookworm) |
| redis | redis | < 6.2.0 | 6.2.0 |
| redis | redis | >= 0 < 5:7.0.1-4 | 5:7.0.1-4 |
| redis | redis | >= 0 < 5:7.0.1-4 | 5:7.0.1-4 |
| redis | redis | >= 0 < 5:7.0.1-4 | 5:7.0.1-4 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
redis: an assertion failure in a primary server by sending a non-administrative command
vendor_redhat·2023-07-15·CVSS 5.9
CVE-2021-31294 [MEDIUM] CWE-617 redis: an assertion failure in a primary server by sending a non-administrative command
redis: an assertion failure in a primary server by sending a non-administrative command
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
A flaw was found in the Redis package. If a replica sends a SET command to its master during a failover, the master crashes on assertion.
Package: 3scale-amp-backend-container (Red Hat 3scale API Management Platform 2) - Affected
Package: 3scale-amp-system-container (Red Hat 3scale API Management Platform 2) - Will not fix
Package: rhacm2/search-api-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2)
Debian
CVE-2021-31294: redis - Redis before 6cbea7d allows a replica to cause an assertion failure in a primary...
vendor_debian·2021·CVSS 5.9
CVE-2021-31294 [MEDIUM] CVE-2021-31294: redis - Redis before 6cbea7d allows a replica to cause an assertion failure in a primary...
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
Scope: local
bookworm: resolved (fixed in 5:7.0.1-4)
bullseye: open
forky: resolved (fixed in 5:7.0.1-4)
sid: resolved (fixed in 5:7.0.1-4)
trixie: resolved (fixed in 5:7.0.1-4)
GHSA
GHSA-g2jg-2qcv-q3h9: Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET c
ghsa_unreviewed·2023-07-16
CVE-2021-31294 [MEDIUM] CWE-617 GHSA-g2jg-2qcv-q3h9: Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET c
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
OSV
CVE-2021-31294: Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET c
osv·2023-07-15·CVSS 5.9
CVE-2021-31294 [MEDIUM] CVE-2021-31294: Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET c
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
No detection rules found.
No public exploits indexed.
https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326fhttps://github.com/redis/redis/issues/8712https://security.netapp.com/advisory/ntap-20230814-0007/https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326fhttps://github.com/redis/redis/issues/8712https://security.netapp.com/advisory/ntap-20230814-0007/
2023-07-15
Published