Home / Companies / Redis / Blog / Post Details
Content Deep Dive

Security Advisory: CVE-2024-31449, CVE-2024-31227, CVE-2024-31228

Blog post from Redis

Post Details
Company
Date Published
Author
Quincy Castro
Word Count
633
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Three security vulnerabilities in Redis have been published recently, including a high-risk Lua library command exploit (CVE-2024-31449), a moderate risk denial-of-service due to unbounded pattern matching (CVE-2024-31228), and another moderate risk denial-of-service due to malformed ACL selectors (CVE-2024-31227). These vulnerabilities require an attacker to gain access to the Redis instance. To protect against these threats, users should follow best practices such as upgrading their Redis versions and securely configuring, deploying, and using Redis. The Redis Cloud service has already been updated with fixes for these vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.