Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The number of redis setups out there which rely on user-uploaded lua scripts and the lua sandbox being sufficient for that has got to be... close to 0?

Like, the lua scripting feature is there for developers to write static trusted lua, check it in, and run transactional stuff etc, and so anyone uploading arbitrary user code as a script is already wildly outside of a normal use of redis.

Seems wild that something which requires using the thing wrong, and also which impacts close to 0 real deployments of the thing, gets a CVSS 10.



Bugs get whatever CVSS the marketing team for the discovering research lab wants them to get. It's literally a Ouija board.


But it says the lua script feature is open by default, so any authenticated (or 60k without auth) can run lua scripts -> use this RCE


Someone will probably worm this eventually and we'll see if it has any true impact.


How about companies providing Redis as a service?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: