CVE-2022-24834 is a critical heap overflow vulnerability in Redis, specifically within the cjson library used for Lua scripting, affecting all versions with Lua scripting support from 2.6 onwards. This flaw allows authenticated and authorized attackers to achieve heap corruption and potentially remote code execution. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low privileges, leading to high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, its high FAUCET Risk Score of 96/100 indicates significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.0, < 6.0.20CPE matchmatch criteria | cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.13CPE matchmatch criteria | cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.12CPE matchmatch criteria | cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.