CVE-2022-24834 is a heap-based buffer overflow in the cjson library used by Redis Lua scripting. A specially crafted Lua script can corrupt heap memory and may potentially lead to remote code execution. The issue affects Redis versions with Lua scripting support from version 2.6 onward and is limited to authenticated, authorized users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (exploit.py) targeting Redis servers vulnerable to CVE-2022-24834. The exploit works by sending a malicious Lua script to the target Redis server using the EVAL command, which executes a bash reverse shell payload. The attacker must provide the Redis host and port, their own listening host and port, and a Lua script file containing the payload (with a [CMD] placeholder for the shell command). The script sets up a netcat listener on the attacker's machine to receive the reverse shell. The exploit leverages the pwn library for network communication and expects the target Redis server to be accessible and vulnerable. The repository also includes a minimal README and a GitHub Actions workflow for Python package testing, but the core functionality is in exploit.py.
This repository contains an operational exploit for CVE-2022-24834, a heap overflow vulnerability in the cjson library of the Lua interpreter embedded in Redis. The exploit consists of two main files: 'exploit.lua', which is a Lua script that leverages the vulnerability to achieve arbitrary code execution, and 'redis_cve-2022-24834.py', a Python script that automates the exploitation process. The Python script connects to a target Redis server (default port 6379), starts a reverse shell listener (default port 4444), and sends the malicious Lua script via the EVAL command. The Lua script is dynamically patched with a reverse shell payload that connects back to the attacker's machine. The exploit has been tested successfully against Redis versions 6.2.12 and 7.0.11 on Ubuntu 20.04 and Debian 11. The attack vector is network-based, requiring access to the Redis command interface. The exploit provides remote code execution capabilities, resulting in a reverse shell on the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.