STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS software installation account must be restricted to authorized users.

DISA Rule

SV-251211r960960_rule

Vulnerability Number

V-251211

Group Title

SRG-APP-000133-DB-000198

Rule Version

RD6X-00-007400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

User must have root level access to the system prior to installing Redis Enterprise. Without this, the installation will not complete, and no changes will be made. Review the procedure used to install Redis Enterprise. In this procedure, users are capable of selecting their own user to own the software. Typically, this is run under a Redis Labs system user.

To check this requirement, investigate the user used and ensure that only the appropriate people are able to access this account on the host operating system.

Check Contents

To install the software, the user must have root level access to each node it will be installed on. Review the procedure used to install Redis Enterprise. In this procedure, users are capable of selecting their own user to own the software. Typically, this is run under a Redis Labs system user.

To check this requirement, investigate the user used and verify that only the appropriate people are able to access this account on the host operating system.

If more than the appropriate people can access this account, this is a finding.

Vulnerability Number

V-251211

Documentable

False

Rule Version

RD6X-00-007400

Severity Override Guidance

To install the software, the user must have root level access to each node it will be installed on. Review the procedure used to install Redis Enterprise. In this procedure, users are capable of selecting their own user to own the software. Typically, this is run under a Redis Labs system user.

To check this requirement, investigate the user used and verify that only the appropriate people are able to access this account on the host operating system.

If more than the appropriate people can access this account, this is a finding.

Check Content Reference

M

Target Key

5443