CVE-2018-11218 is a critical memory corruption vulnerability affecting the cmsgpack library in the Lua subsystem of Redis versions before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, due to stack-based buffer overflows. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists for Redis Replication Code Execution, indicating readily available exploit code, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.12CPE matchmatch criteria | cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.0.10CPE matchmatch criteria | cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:redislabs:redis:5.0:rc1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
3.4CPE matchmatch criteria | cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.