# Security Advisory: CVE-2022-35951 Redis™

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;Security Advisory: CVE-2022-35951 Redis™ 

Security Advisory: CVE-2022-35951 Redis™
========================================

September 30, 2022 | By [ Carrie Powick](https://www.instaclustr.com/blog/author/carrie-powick/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Security%20Advisory:%20CVE-2022-35951%20Redis%E2%84%A2&url=https://www.instaclustr.com/blog/security-advisory-cve-2022-35951-redis/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/security-advisory-cve-2022-35951-redis/&title=&summary=Security%20Advisory:%20CVE-2022-35951%20Redis%E2%84%A2&source=) 

Soon after the publication of [CVE-2022-35951](https://nvd.nist.gov/vuln/detail/CVE-2022-35951), Instaclustr began investigating its potential impact on our Instaclustr for Redis™ offering. This vulnerability, which exists in Redis version 7.0.0 and greater, can be exploited by an authenticated attacker when a specially crafted XAUTOCLAIM command is executed, which can cause an integer overflow and a follow up heap overflow, which has the potential to allow remote code execution.

We believe that the security controls that exist in our managed service – including but not limited to firewalls, detection, and compartmentalization practices – lower the risk of this vulnerability. However, due to the severity of the vulnerability we have decided that releasing the newer patched version of Redis and subsequently upgrading customers on a vulnerable version (i.e. any Redis 7.0.x versions released prior to Redis 7.0.5) is the best course of action. [Redis 7.0.5](https://github.com/redis/redis/releases/tag/7.0.5) contains the fix and will soon be made available on the Instaclustr Managed Platform. If you have any questions please get in contact with us via our support website.

### Mitigation:

- For customers on Redis 7.0.4:
    - We recommend upgrading to Redis 7.0.5 as soon as it’s available. We will be in touch with affected customers shortly to work out the next steps. We’re aiming to make it available in the coming days.
    - Alternatively, customers who want to take a more proactive stance, can limit access to their Redis cluster to only trusted clients and ensure those clients are secure. This is always good security practice in any case.
- As a further mitigation step, we will immediately be marking Redis 7.0.4 as Legacy Support, as per our [lifecycle policy](https://www.instaclustr.com/support/documentation/useful-information/lifecycle-policy/).

If you have any further queries regarding this vulnerability and how it relates to Instaclustr services, please contact <support@instaclustr.com>.

References: <https://nvd.nist.gov/vuln/detail/CVE-2022-35951>

 



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
