EXPOSURES › CVE-2022-0543
CVE-2022-0543
HIGH ⌖ ON CISA KEV · EXPLOITEDA Debian-specific Redis server flaw allowed remote code execution via a Lua sandbox escape.
The Debian-specific Redis server contained a Lua sandbox escape vulnerability that enabled remote code execution. This is a critical failure for DIB organizations because it allows attackers to execute arbitrary commands on the server, leading to potential data breaches, system compromise, and compliance violations. Organizations must ensure their Redis deployments are patched and avoid relying on Debian-specific configurations that may introduce unpatched vulnerabilities.
Shame score — The vulnerability was actively exploited in the wild (KEV list) and enabled remote code execution, representing a severe, avoidable failure in securing a widely used database server.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.