STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

DISA Rule

SV-251185r960792_rule

Vulnerability Number

V-251185

Group Title

SRG-APP-000033-DB-000084

Rule Version

RD6X-00-000800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

To modify the commands or keys a user is able to access, perform the following steps:

1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Ensure the appropriate role is configured by inspecting the Redis ACL rules and Roles in the Redis ACL and Role sub-tabs.
4. If an appropriate role is not present, create the appropriate role.
5. On the users tab, assign the appropriate role to the user in question.

Check Contents

Review the system documentation to determine if accounts have been set with appropriate, organizationally defined role-based permissions. Compare these settings with the settings on the actual DB.

To find the database id, run the command:
rladmin status extra all.

1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned an appropriate role.

If a user is not assigned an appropriate role, this is a finding.

If the appropriate role is not assigned to a user, or the roles and permission settings are not documented, this is a finding.

Vulnerability Number

V-251185

Documentable

False

Rule Version

RD6X-00-000800

Severity Override Guidance

Review the system documentation to determine if accounts have been set with appropriate, organizationally defined role-based permissions. Compare these settings with the settings on the actual DB.

To find the database id, run the command:
rladmin status extra all.

1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned an appropriate role.

If a user is not assigned an appropriate role, this is a finding.

If the appropriate role is not assigned to a user, or the roles and permission settings are not documented, this is a finding.

Check Content Reference

M

Target Key

5443