What's the CVE story for valkey ? #1236
Unanswered
eric-desrochers
asked this question in
Q&A
Replies: 1 comment 1 reply
-
Redis is much more likely to get a CVE report to them because we are still pretty new. I missed sending security advisories for CVEs that impact us on github, but I'll start doing that as well. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Look like most CVE are still reported to Redis and then backported to Valkey:
#1115
https://linuxsecurity.com/advisories/fedora/fedora-41-valkey-2024-e717420659-security-advisory-updates-e8mrbspx1jim
Seems like Valkey has no security advisory:
https://github.com/valkey-io/valkey/security/advisories
What's the CVE vulnerability story for Valkey to ensure it is secured/detected against newly detected CVE ?
Example:
GHSA-whxg-wx83-85p5
![image](https://private-user-images.githubusercontent.com/98553622/380878998-d63ff61c-05c4-418f-b237-e412d901af06.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkwMTY5NTcsIm5iZiI6MTczOTAxNjY1NywicGF0aCI6Ii85ODU1MzYyMi8zODA4Nzg5OTgtZDYzZmY2MWMtMDVjNC00MThmLWIyMzctZTQxMmQ5MDFhZjA2LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMDglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjA4VDEyMTA1N1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTQxZTBjZDE4MmM2ZDJkOTdmYzI3MTUwY2VlYjMxOTU4YWI5ZWE5NWY5ODE4OWFkYWQzZDlhMjY4NjEwMzYwMTMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.QwSbZJZ1HyBPnHJbhNspDoaogNF9Y_DAQZs9kuJV5iM)
https://www.cve.org/CVERecord?id=CVE-2024-31449
![image](https://private-user-images.githubusercontent.com/98553622/380879177-3384733e-167b-4cad-abc2-c0109536c16e.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkwMTY5NTcsIm5iZiI6MTczOTAxNjY1NywicGF0aCI6Ii85ODU1MzYyMi8zODA4NzkxNzctMzM4NDczM2UtMTY3Yi00Y2FkLWFiYzItYzAxMDk1MzZjMTZlLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMDglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjA4VDEyMTA1N1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWI5ZjdkMDE2NTAwNDc2M2Q3ZjQyZDZmMjkyMDZlOWNmYTU0YTE2ZDdlN2ViZmNjYzRiMTYxZWJlMDBmNzQ2YmUmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.0BtgcVSpFJAhTDomc4jQhlmncRhPi_1_oNNu4TQK4h8)
It was backported in Valkey, but no indication/advertisement that Valkey is vulnerable, just redis is mentionnned.
Beta Was this translation helpful? Give feedback.
All reactions