STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).

DISA Rule

SV-251222r960969_rule

Vulnerability Number

V-251222

Group Title

SRG-APP-000148-DB-000103

Rule Version

RD6X-00-008600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To fix this issue perform the following actions:

To audit this configuration:
1. Log in to Redis Enterprise Administrative Control Plane.
2. Go to databases tab.
3. Select each database and review the configuration by selecting edit.
4. Deselect the default database access tab.

This configuration will break applications designed for use with Redis 5 prior to ACLs.

Check Contents

To audit this configuration:
1. Log in to Redis Enterprise Administrative Control Plane.
2. Go to databases tab.
3. Select the desired database and then the configuration subtab.
4. Verify that Default database access is enabled.

If it is enabled, this is a finding.

Vulnerability Number

V-251222

Documentable

False

Rule Version

RD6X-00-008600

Severity Override Guidance

To audit this configuration:
1. Log in to Redis Enterprise Administrative Control Plane.
2. Go to databases tab.
3. Select the desired database and then the configuration subtab.
4. Verify that Default database access is enabled.

If it is enabled, this is a finding.

Check Content Reference

M

Target Key

5443