using redis 6.0.4,lua CVE vulnerabilities not fixed: CVE-2020-15888 CVE-2020-15889 CVE-2020-15945 CVE-2014-5461
Is there any plan to upgrade or fix it?
Comment From: yossigo
The Lua fix for CVE-2014-5461 is resolved by #7733. As for the other reported Lua vulnerabilities, they seem to have been introduced (and solved) by newer versions of Lua only (Redis uses Lua 5.1).
Comment From: oranagra
Thanks Yossi. closing the issue. @plainee please feel free to respond or re-open if you have other info.