STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.

DISA Rule

SV-251208r1018617_rule

Vulnerability Number

V-251208

Group Title

SRG-APP-000378-DB-000365

Rule Version

RD6X-00-007000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To ensure a regular user is unable to perform updates:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access controls tab.
3. In the users section, review each users role to ensure they are assigned the appropriate permissions.
4. If a user is not assigned appropriate permissions, ensure they are moved to an appropriate role.

Check Contents

Modules may be added to the Redis Enterprise control plane (adminUI) by navigating to the settings tab and then modules. Only admin users can view the settings tab.

To verify that users without explicit privileged status are not able to install modules, do the following:
1. Log in to the Redis Enterprise control plane (adminUI) with a user with administrative privileges.
2. Navigate to the access control tab.
3. Verify that only organizationally defined users have the appropriate privileges.

If a user is not assigned appropriate permissions, this is a finding.

Vulnerability Number

V-251208

Documentable

False

Rule Version

RD6X-00-007000

Severity Override Guidance

Modules may be added to the Redis Enterprise control plane (adminUI) by navigating to the settings tab and then modules. Only admin users can view the settings tab.

To verify that users without explicit privileged status are not able to install modules, do the following:
1. Log in to the Redis Enterprise control plane (adminUI) with a user with administrative privileges.
2. Navigate to the access control tab.
3. Verify that only organizationally defined users have the appropriate privileges.

If a user is not assigned appropriate permissions, this is a finding.

Check Content Reference

M

Target Key

5443