CVE-2022-0543
Debian-specific Redis Server Lua Sandbox Escape Vulnerability
- Published
- Feb 18, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- debian
- Evidence observed
- Mar 28, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Sources
6- CVE-2022-0543Exploit
CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行
PoC for CVE-2022-0543 – Redis Remote Code Execution (RCE)
- CVE-2022-0543-Home-LabResearch
CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.