STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (stored procedures, functions, triggers, links to software external to Redis Enterprise DBMS, etc.) must be restricted to authorized users.

DISA Rule

SV-251213r960960_rule

Vulnerability Number

V-251213

Group Title

SRG-APP-000133-DB-000362

Rule Version

RD6X-00-007700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To ensure that users are provided the appropriate permissions that they are authorized to use, check each user's assigned roles.
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Navigate to the users tab.
4. Locate desired user.
5. Assign appropriate permission based on desired authorization level.

Check Contents

To check each user's assigned role:
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Navigate to the users tab.
4. Review all roles assigned to a user and verify that user is given the appropriate role for their authorization level.

If the user is not given the appropriate role, this is a finding.

Vulnerability Number

V-251213

Documentable

False

Rule Version

RD6X-00-007700

Severity Override Guidance

To check each user's assigned role:
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Navigate to the users tab.
4. Review all roles assigned to a user and verify that user is given the appropriate role for their authorization level.

If the user is not given the appropriate role, this is a finding.

Check Content Reference

M

Target Key

5443