[GH-ISSUE #2304] Redis Vulnerable #1423

Closed
opened 2026-03-02 02:23:05 +03:00 by kerem · 2 comments
Owner

Originally created by @desenvolvimento-stateraTI on GitHub (Oct 8, 2025).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/2304

I saw a news item about CVE-2025-49844 that Redis has a critical vulnerability with a score of 9.9. The request is that it be updated to version 8.2.2. Can I do this update or will it impact the use of TRMM? Is there a forecast if a system update is necessary?

Originally created by @desenvolvimento-stateraTI on GitHub (Oct 8, 2025). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/2304 I saw a news item about CVE-2025-49844 that Redis has a critical vulnerability with a score of 9.9. The request is that it be updated to version 8.2.2. Can I do this update or will it impact the use of TRMM? Is there a forecast if a system update is necessary?
kerem closed this issue 2026-03-02 02:23:06 +03:00
Author
Owner

@wh1te909 commented on GitHub (Oct 8, 2025):

not applicable, this exploit requires network access. trmm's redis binds to localhost.

<!-- gh-comment-id:3379205157 --> @wh1te909 commented on GitHub (Oct 8, 2025): not applicable, this exploit requires network access. trmm's redis binds to localhost.
Author
Owner

@desenvolvimento-stateraTI commented on GitHub (Oct 8, 2025):

Ok, Thanks

<!-- gh-comment-id:3379205891 --> @desenvolvimento-stateraTI commented on GitHub (Oct 8, 2025): Ok, Thanks
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#1423
No description provided.