CVE-2022-36021
MediumAdvisory
Published 1 Mar 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.605
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Redis string pattern matching can be abused to achieve Denial of Service
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| redisbitnami | 6.0.8-0, 6.0.12-0, 6.2.7-150, 7.0.8-0+1 more | 6.0.18 | 5 |
| redisdeb | 5:5.0.7-2ubuntu0.1 | 5:5.0.7-2ubuntu0.1+esm2 | 2 |
- OSV records
- BIT-redis-2022-36021UBUNTU-CVE-2022-36021
- Also known as
- BIT-keydb-2022-36021, BIT-valkey-2022-36021, GHSA-jr7j-rfj5-8xqv, USN-6531-1
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| chatwootchatwootVerified publisher | 2.0.24 | 1 of 3See more | 9,203 |
| netris-controllernetrisai | 2.8.2 | 1 of 14See more | 30,326 |
| supportpalevilgn0me | 0.1.6 | 1 of 1See more | 20,933 |
| redisredisVerified publisher | 0.1.1 | 1 of 1See more | 1,594 |
| redisredis-arm | 17.8.0 | 1 of 1See more | 1,906 |
| redis-high-availabilitysomeblackmagic | 1.3.10 | 1 of 3See more | 3,148 |
| testing-multitoolsomeblackmagic | 0.1.2 | 1 of 1See more | 30,687 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnamilegacy/ | 7788b908dd0d | redis | 6.0.18 | 1 |
| bitnamilegacy/ | bf01d031ba8c | redis | 6.0.18 | 1 |
| netrisai/ | a4c0140d1696 | redis | 6.0.18 | 1 |
| someblackmagic/ | 6eca64b6b440 | redis | 5:5.0.7-2ubuntu0.1+esm2 | 1 |
| ghcr.io/ | 118a403046f7 | redis | 6.0.18 | 1 |
| mcr.microsoft.com/ | e1e9cf5297a6 | redis | 6.0.18 | 1 |
| public.ecr.aws/ | 573779e57fae | redis | 5:5.0.7-2ubuntu0.1+esm2 | 1 |