CVE-2022-24834 - CVE House
Back to Database
Status published High CVE-2022-24834

Heap overflow issue with the Lua cjson library used by Redis

Vulnerability Description

Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24834

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

redis
Vulnerable Versions:
>= 7.0.0, < 7.0.12, >= 6.2.0, < 6.2.13, >= 6.0.0, < 6.0.20

Timeline

Official Publish: July 13th, 2023
Last Modified: February 13th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)