Redis에서 심각한 RCE 취약점이 발견되어 보안 업데이트가 진행됐다.
Redis는 연구자들이 인증된 원격 코드 실행(PoC)을 공개한 후 7개의 보안 업데이트를 발표했다. 취약점은 Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0에서 발견됐으며, 특정 명령어들의 조합을 통해 악용될 수 있다. Redis의 메모리 결함이 원격 코드 실행으로 이어질 수 있다는 설명이다.
Serious RCE vulnerabilities were found in Redis, prompting security updates.
Redis released seven security updates after researchers published authenticated remote code execution (RCE) proof-of-concepts. The vulnerabilities were found in Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, which can be exploited using specific command combinations. It was noted that underlying memory flaws could lead to remote code execution.