Skip to content

[Security] CVE-2022-24735: Lua sandbox escape via loadstring() #958

Description

@vulgraph

Vulnerability

KeyDB inherits CVE-2022-24735 from Redis — Lua sandbox escape via loadstring(). An authenticated user can bypass ACL restrictions.

Reproduction

keydb-cli EVAL "return loadstring('return 1')()" 0

Returns 1 — confirming loadstring is available. Combined with setfenv/getfenv, an attacker can execute arbitrary Redis commands bypassing ACL.

Tested Version

KeyDB latest master (git sha 603ebb27).

Suggested Fix

Remove loadstring from the Lua sandbox, as Redis did in version 6.2.7+.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions