Vulnerabilities > CVE-2021-31294 - Reachable Assertion vulnerability in Redis

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
redis
CWE-617

Summary

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.

Vulnerable Configurations

Part Description Count
Application
Redis
158

Common Weakness Enumeration (CWE)