<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to update Redis vulnerable version (#RediShell) ?]]></title><description><![CDATA[<h1>Description</h1>
<blockquote>
<p dir="auto">Cloudron common redis image is vulnerable to critical vulnerability (CVE-2025-49844 - 10 CVSS)</p>
</blockquote>
<h2>Logs</h2>
<p dir="auto">Logs says it's version 7.4.2, fixed version is 7.4.6</p>
<p dir="auto">Gitlab</p>
<pre><code>Oct 08 12:06:24 13:C 08 Oct 2025 10:06:24.722 * oO0OoO0OoO0Oo Redis is starting oO0OoO0OoO0Oo
Oct 08 12:06:24 13:C 08 Oct 2025 10:06:24.722 * Redis version=7.4.2, bits=64, commit=00000000, modified=0, pid=13, just started
Oct 08 12:06:24 13:C 08 Oct 2025 10:06:24.722 * Configuration loaded
Oct 08 12:06:24 13:M 08 Oct 2025 10:06:24.722 * monotonic clock: POSIX clock_gettime
Oct 08 12:06:24 13:M 08 Oct 2025 10:06:24.724 # Failed to write PID file: Permission denied
Oct 08 12:06:24 13:M 08 Oct 2025 10:06:24.724 * Running mode=standalone, port=6379.
Oct 08 12:06:24 13:M 08 Oct 2025 10:06:24.725 * Server initialized
Oct 08 12:06:24 13:M 08 Oct 2025 10:06:24.725 * Loading RDB produced by version 7.4.2
</code></pre>
<p dir="auto">Same with N8n:</p>
<pre><code>Oct 08 12:19:46 13:C 08 Oct 2025 10:19:46.483 * oO0OoO0OoO0Oo Redis is starting oO0OoO0OoO0Oo
Oct 08 12:19:46 13:C 08 Oct 2025 10:19:46.483 * Redis version=7.4.2, bits=64, commit=00000000, modified=0, pid=13, just started
Oct 08 12:19:46 13:C 08 Oct 2025 10:19:46.483 * Configuration loaded
Oct 08 12:19:46 13:M 08 Oct 2025 10:19:46.483 * monotonic clock: POSIX clock_gettime
Oct 08 12:19:46 13:M 08 Oct 2025 10:19:46.485 # Failed to write PID file: Permission denied
Oct 08 12:19:46 13:M 08 Oct 2025 10:19:46.485 * Running mode=standalone, port=6379.
Oct 08 12:19:46 13:M 08 Oct 2025 10:19:46.485 * Server initialized
Oct 08 12:19:46 13:M 08 Oct 2025 10:19:46.486 * Loading RDB produced by version 7.4.2
</code></pre>
<p dir="auto">And all other apps using redis, probably the same redis image is used</p>
<h1>System Details</h1>
<h2>Cloudron Version</h2>
<pre><code>{
  "version": "8.3.2"
}
</code></pre>
<h2>Ubuntu Version</h2>
<pre><code>No LSB modules are available.
Distributor ID:	Ubuntu
Description:	Ubuntu 24.04.2 LTS
Release:	24.04
Codename:	noble
</code></pre>
<h2>Cloudron installation method</h2>
<p dir="auto">Manual with <code>./cloudron-setup</code></p>
]]></description><link>https://forum.cloudron.io/topic/14379/how-to-update-redis-vulnerable-version-redishell</link><generator>RSS for Node</generator><lastBuildDate>Wed, 10 Jun 2026 19:20:07 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/14379.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Oct 2025 10:36:47 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to update Redis vulnerable version (#RediShell) ? on Thu, 09 Oct 2025 12:36:44 GMT]]></title><description><![CDATA[<p dir="auto">I updated redis to 8.2.2 - <a href="https://git.cloudron.io/platform/box/-/commit/3547be34010a737d9fbd5aed5bb9e787eeff5456" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/platform/box/-/commit/3547be34010a737d9fbd5aed5bb9e787eeff5456</a></p>
]]></description><link>https://forum.cloudron.io/post/113579</link><guid isPermaLink="true">https://forum.cloudron.io/post/113579</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 09 Oct 2025 12:36:44 GMT</pubDate></item><item><title><![CDATA[Reply to How to update Redis vulnerable version (#RediShell) ? on Thu, 09 Oct 2025 03:35:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Will you be looking at better alternatives as suggested previously on the forum?</p>
]]></description><link>https://forum.cloudron.io/post/113560</link><guid isPermaLink="true">https://forum.cloudron.io/post/113560</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Thu, 09 Oct 2025 03:35:29 GMT</pubDate></item><item><title><![CDATA[Reply to How to update Redis vulnerable version (#RediShell) ? on Wed, 08 Oct 2025 12:50:49 GMT]]></title><description><![CDATA[<p dir="auto">More info on the vulnerability at <a href="https://thehackernews.com/2025/10/13-year-redis-flaw-exposed-cvss-100.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2025/10/13-year-redis-flaw-exposed-cvss-100.html</a></p>
<p dir="auto">Given that redis on Cloudron isn't exposed to the public internet, only apps have access to it and also there via authentication, the risk seems very limited unless an app is compromised itself at which point the app itself can do more harm anyways. Also note that redis instances on Cloudron are per-app and thus well isolated.</p>
<p dir="auto">We will still update it normally in time, probably with Cloudron 9 patch release.</p>
]]></description><link>https://forum.cloudron.io/post/113553</link><guid isPermaLink="true">https://forum.cloudron.io/post/113553</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Wed, 08 Oct 2025 12:50:49 GMT</pubDate></item></channel></rss>