{"id":"CVE-2022-0543","aliases":["BIT-redis-2022-0543"],"url":"https://o3.security/vulnerability/CVE-2022-0543","summary":null,"details":"It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.","published":"2022-02-18T20:15:17.583Z","modified":"2026-03-15T22:43:19.293464Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.99351,"percentile":0.99938,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":13,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0543"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-security-announce/2022/msg00048.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220331-0004/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5081"},{"type":"ADVISORY","url":"https://www.ubercomp.com/posts/2022-01-20_redis_on_debian_rce"},{"type":"FIX","url":"https://bugs.debian.org/1005787"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/166885/Redis-Lua-Sandbox-Escape.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-15T22:43:19.293464Z"}}