STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must prevent non-privileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

DISA Rule

SV-251188r961353_rule

Vulnerability Number

V-251188

Group Title

SRG-APP-000340-DB-000304

Rule Version

RD6X-00-001000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To ensure that a non-privileged user is not granted a non-default role, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. Assign users an appropriate role, and if necessary, create a new role for the user.
5. Modify and save the users' new role after ensuring the role is provided with the appropriate permissions.

Check Contents

To verify this, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. For users without the need to modify the database, verify they are given a viewer or none for cluster management in the roles tab.
5. For users with access to databases, verify they are given the default role "Not Dangerous" or a more restrictive role that does not allow access to the dangerous command category.

If a non-privileged user is granted a non-default role, this is a finding.

Vulnerability Number

V-251188

Documentable

False

Rule Version

RD6X-00-001000

Severity Override Guidance

To verify this, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. For users without the need to modify the database, verify they are given a viewer or none for cluster management in the roles tab.
5. For users with access to databases, verify they are given the default role "Not Dangerous" or a more restrictive role that does not allow access to the dangerous command category.

If a non-privileged user is granted a non-default role, this is a finding.

Check Content Reference

M

Target Key

5443