STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must prevent unauthorized and unintended information transfer via shared system resources.

DISA Rule

SV-251246r961149_rule

Vulnerability Number

V-251246

Group Title

SRG-APP-000243-DB-000373

Rule Version

RD6X-00-011400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Users and ACLs can be created and modified from the Redis Enterprise UI by navigating to the access control tab as an admin user. Update the user roles and ACLs to reflect organizational requirements.

Check Contents

Verify all returned users with security permissions are documented as requiring the permissions.

In the web UI, select access control >> Redis acls.

Verify that the documented users have the correct ACL(s) assigned to them by clicking the "Used By" link for each listed ACL.

Verify that all documented ACLs match each of the listed ACLs.

If "Redis ACL name" and "Used By" do not match the documentation, this is a finding.

Vulnerability Number

V-251246

Documentable

False

Rule Version

RD6X-00-011400

Severity Override Guidance

Verify all returned users with security permissions are documented as requiring the permissions.

In the web UI, select access control >> Redis acls.

Verify that the documented users have the correct ACL(s) assigned to them by clicking the "Used By" link for each listed ACL.

Verify that all documented ACLs match each of the listed ACLs.

If "Redis ACL name" and "Used By" do not match the documentation, this is a finding.

Check Content Reference

M

Target Key

5443