Updated on 2023-03-15 GMT+08:00

Vulnerability Fixing Policies

Vulnerability Fixing Time

  • High-risk vulnerabilities

    Distributed Cache Service (DCS) fixes vulnerabilities within one month after the Redis community detects them and releases fixing solutions. The fixing policies are the same as those of the community.

  • Other vulnerabilities

    Upgrade versions to fix other vulnerabilities.

Fixing Statement

To prevent customers from being exposed to unexpected risks, DCS does not provide other information about the vulnerability except the vulnerability background, details, technical analysis, affected functions/versions/scenarios, solutions, and reference information.

In addition, DCS provides the same information for all customers to protect all customers equally. DCS will not notify individual customers in advance.

DCS does not develop or release intrusive code (or code for verification) to exploit vulnerabilities.