V-251246
Redis Enterprise 6.x Security Technical Implementation Guide
Title
Redis Enterprise DBMS must prevent unauthorized and unintended information transfer via shared system resources.
Description
<VulnDiscussion>The purpose of this control is to prevent information, including encrypted representations of information, produced by the actions of a prior user/role (or the actions of a process acting on behalf of a prior user/role) from being available to any current user/role (or current process) that obtains access to a shared system resource (e.g., registers, main memory, secondary storage) after the resource has been released back to the information system. Control of information in shar...
Fix Text (Documentation Requirement)
Users and ACLs can be created and modified from the Redis Enterprise UI by navigating to the access control tab as an admin user. Update the user roles and ACLs to reflect organizational requirements.