{"id":"BIT-valkey-2021-31294","details":"Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.","aliases":["BIT-keydb-2021-31294","BIT-redis-2021-31294","CVE-2021-31294"],"modified":"2025-06-10T09:28:51.919902Z","published":"2024-08-22T19:46:26.156Z","database_specific":{"cpes":["cpe:2.3:a:valkey-io:valkey:*:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48"},{"type":"WEB","url":"https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f"},{"type":"WEB","url":"https://github.com/redis/redis/issues/8712"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230814-0007/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31294"}],"affected":[{"package":{"name":"valkey","ecosystem":"Bitnami","purl":"pkg:bitnami/valkey"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.2.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/valkey/BIT-valkey-2021-31294.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}],"schema_version":"1.7.3"}