CVE-2024-51480

HIGH

RedisTimeSeries Commands - Integer Overflow Code Execution

Title source: manual
STIX 2.1

Description

RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially crafted command arguments may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This vulnerability is fixed in 1.6.20, 1.8.15, 1.10.15, and 1.12.3.

References (1)

Core 1

Scores

CVSS v3 7.0
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122 CWE-190
Status published
Products (4)
RedisTimeSeries/RedisTimeSeries >= 1.0.0, < 1.6.20
RedisTimeSeries/RedisTimeSeries >= 1.10.0, < 1.10.15
RedisTimeSeries/RedisTimeSeries >= 1.12.0, < 1.12.3
RedisTimeSeries/RedisTimeSeries >= 1.8.0, < 1.8.15
Published Jan 08, 2025
Tracked Since Feb 18, 2026