

Terjemahan disediakan oleh mesin penerjemah. Jika konten terjemahan yang diberikan bertentangan dengan versi bahasa Inggris aslinya, utamakan versi bahasa Inggris.

# Kerentanan dan Eksposur Umum (CVE): Kerentanan keamanan ditangani di ElastiCache
<a name="cve"></a>

Kerentanan dan Eksposur Umum (CVE) adalah daftar entri untuk kerentanan keamanan siber yang diketahui publik. Setiap entri adalah tautan yang berisi nomor identifikasi, deskripsi, dan setidaknya satu referensi publik. Anda dapat menemukan di halaman ini daftar kerentanan keamanan yang telah diatasi di ElastiCache, serta CVE yang tidak mempengaruhi ElastiCache. 

Kami menyarankan Anda selalu meningkatkan ke versi ElastiCache Valkey, Redis OSS atau ElastiCache Memcached terbaru untuk dilindungi dari kerentanan yang diketahui. Saat mengoperasikan Cache ElastiCache Tanpa Server, perbaikan CVE secara otomatis diterapkan ke cache Anda. Saat mengoperasikan cluster berbasis node dengan Valkey atau Redis OSS, meng ElastiCache ekspos komponen PATCH. Misalnya, saat menggunakan ElastiCache untuk Redis OSS versi 6.2.6, versi utama adalah 6, versi minor adalah 2, dan versi patch adalah 6. Versi PATCH adalah untuk perbaikan bug yang kompatibel ke belakang, perbaikan keamanan, dan perubahan non-fungsional. 

## CVE ditangani di Amazon ElastiCache
<a name="cve-addressed"></a>

Tabel berikut mencantumkan CV dan versi ElastiCache mesin di mana mereka ditangani. Tanda centang (✓) menunjukkan CVE ditangani dalam versi tersebut. N/A menunjukkan CVE tidak mempengaruhi versi mesin tersebut. Jika cluster ElastiCache Valkey atau Redis OSS Anda menjalankan versi tanpa perbaikan keamanan, Anda dapat meningkatkan ke versi ElastiCache Valkey atau Redis OSS yang lebih baru yang berisi perbaikan, atau jika Anda menggunakan versi yang berisi perbaikan, pastikan Anda memiliki pembaruan layanan terbaru yang diterapkan dengan merujuk ke. [Mengelola pembaruan layanan untuk cluster berbasis node](Self-Service-Updates.md#managing-updates) Untuk informasi selengkapnya tentang versi ElastiCache engine yang didukung dan cara memutakhirkan, lihat[Versi mesin dan peningkatan di ElastiCache](engine-versions.md).

**catatan**  
Tanda bintang (\*) pada tabel berikut menunjukkan bahwa Anda harus menerapkan pembaruan layanan terbaru untuk cluster yang menjalankan versi yang ditentukan untuk mengatasi kerentanan keamanan. Untuk informasi selengkapnya tentang cara memverifikasi bahwa Anda memiliki pembaruan layanan terbaru yang diterapkan untuk versi yang dijalankan cluster Anda, lihat[Mengelola pembaruan layanan untuk cluster berbasis node](Self-Service-Updates.md#managing-updates).


| CVE | Valkey 9.1 | Valkey 9.0 | Valkey 8.2 | Valkey 8.1 | Valkey 8.0 | Valkey 7.2 | Redis OSS 7.1 | Redis OS 7.0 | Redis OSS 6.2 | Redis OS 6.0 | Redis OS 5.0 | Redis OS 4.0 | 
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | 
| [CVE-2026-66373](https://www.cve.org/CVERecord?id=CVE-2026-66373)\* | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | 
| [CVE-2026-25589](https://www.cve.org/CVERecord?id=CVE-2026-25589) | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | 
| [CVE-2026-25588](https://www.cve.org/CVERecord?id=CVE-2026-25588) | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | 
| [CVE-2026-25243](https://www.cve.org/CVERecord?id=CVE-2026-25243)\* | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | 
| [CVE-2026-23631](https://www.cve.org/CVERecord?id=CVE-2026-23631) | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | 
| [CVE-2026-23479](https://www.cve.org/CVERecord?id=CVE-2026-23479)\* | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | 
| [CVE-2025-67733](https://www.cve.org/CVERecord?id=CVE-2025-67733)\* | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | N/A | 
| [CVE-2025-49844](https://www.cve.org/CVERecord?id=CVE-2025-49844)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-49819](https://www.cve.org/CVERecord?id=CVE-2025-49819)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-48367](https://www.cve.org/CVERecord?id=CVE-2025-48367)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-46844](https://www.cve.org/CVERecord?id=CVE-2025-46844)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-46818](https://www.cve.org/CVERecord?id=CVE-2025-46818)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-46817](https://www.cve.org/CVERecord?id=CVE-2025-46817)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-32023](https://www.cve.org/CVERecord?id=CVE-2025-32023)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2025-27151](https://www.cve.org/CVERecord?id=CVE-2025-27151)\* | N/A | N/A | N/A | ✓ | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 
| [CVE-2025-21605](https://www.cve.org/CVERecord?id=CVE-2025-21605)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2024-46981](https://www.cve.org/CVERecord?id=CVE-2024-46981) | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2024-31449](https://www.cve.org/CVERecord?id=CVE-2024-31449)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2024-31228](https://www.cve.org/CVERecord?id=CVE-2024-31228)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2024-31227](https://www.cve.org/CVERecord?id=CVE-2024-31227)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2023-41056](https://www.cve.org/CVERecord?id=CVE-2023-41056)\* | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | N/A | N/A | N/A | N/A | N/A | 
| [CVE-2023-28425](https://www.cve.org/CVERecord?id=CVE-2023-28425)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | N/A | N/A | N/A | N/A | 
| [CVE-2023-25155](https://www.cve.org/CVERecord?id=CVE-2023-25155) | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2023-22458](https://www.cve.org/CVERecord?id=CVE-2023-22458) | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2022-36021](https://www.cve.org/CVERecord?id=CVE-2022-36021)\* | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2022-35977](https://www.cve.org/CVERecord?id=CVE-2022-35977)\* | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2022-35951](https://www.cve.org/CVERecord?id=CVE-2022-35951)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | N/A | N/A | N/A | N/A | 
| [CVE-2022-31144](https://www.cve.org/CVERecord?id=CVE-2022-31144)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | N/A | N/A | N/A | N/A | 
| [CVE-2022-24834](https://www.cve.org/CVERecord?id=CVE-2022-24834)\* | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | 
| [CVE-2021-41099](https://www.cve.org/CVERecord?id=CVE-2021-41099)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32762](https://www.cve.org/CVERecord?id=CVE-2021-32762)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32761](https://www.cve.org/CVERecord?id=CVE-2021-32761)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32687](https://www.cve.org/CVERecord?id=CVE-2021-32687)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32675](https://www.cve.org/CVERecord?id=CVE-2021-32675)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32672](https://www.cve.org/CVERecord?id=CVE-2021-32672)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32628](https://www.cve.org/CVERecord?id=CVE-2021-32628)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32627](https://www.cve.org/CVERecord?id=CVE-2021-32627)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32626](https://www.cve.org/CVERecord?id=CVE-2021-32626)\* | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-32625](https://www.cve.org/CVERecord?id=CVE-2021-32625)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-29478](https://www.cve.org/CVERecord?id=CVE-2021-29478)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-29477](https://www.cve.org/CVERecord?id=CVE-2021-29477)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 
| [CVE-2021-21309](https://www.cve.org/CVERecord?id=CVE-2021-21309)\* | N/A | N/A | N/A | N/A | N/A | N/A | ✓ | ✓ | ✓ | ✓ | N/A | N/A | 

## CVE yang tidak memengaruhi Amazon ElastiCache
<a name="cve-not-affected"></a>

CV berikut tidak memengaruhi Amazon ElastiCache untuk Valkey atau Redis OSS.
+ [CVE-2026-21864](https://www.cve.org/CVERecord?id=CVE-2026-21864)
+ [CVE-2026-21863](https://www.cve.org/CVERecord?id=CVE-2026-21863)
+ [CVE-2024-51741](https://www.cve.org/CVERecord?id=CVE-2024-51741)
+ [CVE-2023-45145](https://www.cve.org/CVERecord?id=CVE-2023-45145)
+ [CVE-2023-28856](https://www.cve.org/CVERecord?id=CVE-2023-28856)
+ [CVE-2022-24736](https://www.cve.org/CVERecord?id=CVE-2022-24736)
+ [CVE-2022-24735](https://www.cve.org/CVERecord?id=CVE-2022-24735)