← Back to CVE List
Vulnerability Intelligence Report
Debian-specific Redis Server Lua Sandbox Escape Vulnerability

CVE-2022-0543

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:99.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-862 ↗CWE-862 Missing Authorization

Affected Products & Versions

Vendor Product Affected Versions
Debian redis n/a (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.670%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDebian GNU/Linux · Vendor · USA
Reserved2022-02-08T00:00:00
Published2022-02-18T19:25:16
Patch Date2022-02-18
Last Updated2025-10-21T23:15:45

LINK COPIED TO CLIPBOARD