Vulnerability
KeyDB inherits CVE-2022-24735 from Redis — Lua sandbox escape via loadstring(). An authenticated user can bypass ACL restrictions.
Reproduction
keydb-cli EVAL "return loadstring('return 1')()" 0
Returns 1 — confirming loadstring is available. Combined with setfenv/getfenv, an attacker can execute arbitrary Redis commands bypassing ACL.
Tested Version
KeyDB latest master (git sha 603ebb27).
Suggested Fix
Remove loadstring from the Lua sandbox, as Redis did in version 6.2.7+.
Vulnerability
KeyDB inherits CVE-2022-24735 from Redis — Lua sandbox escape via
loadstring(). An authenticated user can bypass ACL restrictions.Reproduction
Returns
1— confirmingloadstringis available. Combined withsetfenv/getfenv, an attacker can execute arbitrary Redis commands bypassing ACL.Tested Version
KeyDB latest master (git sha
603ebb27).Suggested Fix
Remove
loadstringfrom the Lua sandbox, as Redis did in version 6.2.7+.