CVE-2020-13151 is a critical vulnerability in Aerospike Community Edition (prior to 4.9.0.10 and 5.0.0.7) that allows unauthenticated remote attackers to submit and execute arbitrary Lua user-defined functions (UDFs) as part of a database query. The vulnerability arises from insufficient blacklisting of dangerous Lua functions: while os.execute() was blocked, io.popen() was not, enabling attackers to execute arbitrary OS commands on all cluster nodes with the privileges of the Aerospike service account. The community edition's lack of authentication further exacerbates the risk, making exploitation trivial for anyone with network access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (POC) exploit for CVE-2020-13151, a remote command execution vulnerability in Aerospike Server versions prior to 5.1.0.3. The exploit consists of two main files: 'exploit.py' (Python) and 'poc.lua' (Lua UDF). The Python script connects to a target Aerospike server, checks its version, populates a dummy record, registers the malicious Lua UDF, and then triggers arbitrary command execution via the UDF. The attacker can specify a custom command or use built-in reverse shell payloads (Python or netcat-based), requiring the attacker to provide a listening host and port. The Lua UDF leverages 'io.popen' to bypass restrictions on 'os.execute', allowing arbitrary shell command execution on the server. The exploit requires the attacker to have sufficient privileges to register and execute UDFs, or for the Aerospike cluster to have security disabled. The repository is structured as a typical POC, with a README, the main exploit script, and the UDF payload. Notable endpoints include the default Aerospike port (3000) and temporary files used for shell access.
This repository contains a single Metasploit module (modules/exploits/linux/misc/aerospike_database_udf_cmd_exec.rb) that exploits CVE-2020-13151, a remote code execution vulnerability in Aerospike Database Community Edition versions prior to 5.1.0.3. The vulnerability arises from the ability to upload and execute Lua UDFs that can call os.execute, allowing arbitrary command execution as the Aerospike service user. The module connects to the Aerospike service (default TCP port 3000), uploads a malicious Lua UDF, and triggers it to execute attacker-supplied commands or payloads. It supports both direct command execution and staged payloads (e.g., Meterpreter reverse shell). The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The only code file is written in Ruby and is structured according to Metasploit conventions, with clear methods for checking vulnerability, uploading/removing UDFs, and executing payloads. The main fingerprintable endpoints are the Aerospike service port (3000/tcp) and the UDF Lua directory on the target system.
This repository provides a working exploit for CVE-2020-13151, a command execution vulnerability in Aerospike Database versions prior to 5.1.0.3. The exploit consists of three main files: a Python script (cve2020-13151.py) for automated exploitation, a Lua script (poc.lua) that acts as a malicious User Defined Function (UDF) to execute arbitrary shell commands, and a shell script (run-poc.sh) to set up a vulnerable Aerospike environment using Docker. The Python script connects to the Aerospike server, checks its version, registers the malicious UDF, and then triggers command execution, supporting both arbitrary shell commands and reverse shell payloads (Python or netcat-based). The Lua UDF leverages io.popen to bypass restrictions on os.execute and can be used interactively or via the Python script. The exploit requires access to the Aerospike server with sufficient privileges to register and execute UDFs. The repository is well-structured for both manual and automated exploitation and demonstrates the vulnerability's impact by allowing full command execution on the target server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.