SV-251188r961353_rule
V-251188
SRG-APP-000340-DB-000304
RD6X-00-001000
CAT II
10
To ensure that a non-privileged user is not granted a non-default role, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. Assign users an appropriate role, and if necessary, create a new role for the user.
5. Modify and save the users' new role after ensuring the role is provided with the appropriate permissions.
To verify this, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. For users without the need to modify the database, verify they are given a viewer or none for cluster management in the roles tab.
5. For users with access to databases, verify they are given the default role "Not Dangerous" or a more restrictive role that does not allow access to the dangerous command category.
If a non-privileged user is granted a non-default role, this is a finding.
V-251188
False
RD6X-00-001000
To verify this, perform the following steps:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access control tab.
3. Navigate to the users tab and review the roles for users.
4. For users without the need to modify the database, verify they are given a viewer or none for cluster management in the roles tab.
5. For users with access to databases, verify they are given the default role "Not Dangerous" or a more restrictive role that does not allow access to the dangerous command category.
If a non-privileged user is granted a non-default role, this is a finding.
M
5443