Skip to content

Comment on An unexpected Redis sandbox escape affecting Debian-based distrosparent

Comments

If I understand correctly this RCE is mostly a big concern to hosts that don't make use of redis authentication, as eval is locked behind it? Some quick testing on my end suggests the eval command is parsed before authentication check but requires authentication for execution, but I may be wrong here.

In a perfect world we can all update immediately but when we still have some servers in Ubuntu 16.04..

Most people probably don't use Redis authentication, and most servers are configured to not require it (including the Debian/Ubuntu defaults).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.