It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5:5.0.7-2ubuntu0.1", "binary_name": "redis" }, { "binary_version": "5:5.0.7-2ubuntu0.1", "binary_name": "redis-sentinel" }, { "binary_version": "5:5.0.7-2ubuntu0.1", "binary_name": "redis-server" }, { "binary_version": "5:5.0.7-2ubuntu0.1", "binary_name": "redis-tools" }, { "binary_version": "5:5.0.7-2ubuntu0.1", "binary_name": "redis-tools-dbgsym" } ] }