STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Access to external executables must be disabled or restricted.

DISA Rule

SV-251219r960963_rule

Vulnerability Number

V-251219

Group Title

SRG-APP-000141-DB-000093

Rule Version

RD6X-00-008300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To add or remove modules or executables:
1. Log in to the Redis Enterprise web UI as an admin user.
2. Navigate to the settings and then Redis modules tabs. From here, modules may be freely added or removed.

Check Contents

Redis Enterprise has this feature available if any object used is approved by the ISSO. By default, external executables are not included in Redis Enterprise, and only admin users on the Redis Enterprise web UI or admins who have direct access to the server can add them.

To determine what modules or executables are applied:
1. Log in to the Redis Enterprise web UI as an admin user.
2. Navigate to the settings and then Redis modules tabs.

Verify that no unapproved external executables exist.

If external executables do exist and are not approved by the ISSO, this is a finding.

Vulnerability Number

V-251219

Documentable

False

Rule Version

RD6X-00-008300

Severity Override Guidance

Redis Enterprise has this feature available if any object used is approved by the ISSO. By default, external executables are not included in Redis Enterprise, and only admin users on the Redis Enterprise web UI or admins who have direct access to the server can add them.

To determine what modules or executables are applied:
1. Log in to the Redis Enterprise web UI as an admin user.
2. Navigate to the settings and then Redis modules tabs.

Verify that no unapproved external executables exist.

If external executables do exist and are not approved by the ISSO, this is a finding.

Check Content Reference

M

Target Key

5443