REDHAT-BUG-1390588: Low severity ioredis vulnerability
It was found that redis set weak permissions on certain files that could potentially contain sensitive information:
-rw-r--r--. 1 redis root 41599 Feb 8 2016 /etc/redis.conf -rw-r--r--. 1 redis root 7355 Feb 8 2016 /etc/redis-sentinel.conf drwxr-xr-x. 2 redis redis 4096 Sep 9 14:29 /var/lib/redis
This issue was originally reported in bug 1374700.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1390588?
The severity of REDHAT-BUG-1390588 is considered moderate due to weak file permissions that could expose sensitive information.
How do I fix REDHAT-BUG-1390588?
To fix REDHAT-BUG-1390588, you should tighten the file permissions on /etc/redis.conf and /etc/redis-sentinel.conf to restrict access.
What files are affected by REDHAT-BUG-1390588?
The affected files in REDHAT-BUG-1390588 include /etc/redis.conf and /etc/redis-sentinel.conf.
Who is impacted by REDHAT-BUG-1390588?
Users running Redis with default configurations are impacted by REDHAT-BUG-1390588 due to the weak file permissions.
What could happen if REDHAT-BUG-1390588 is not addressed?
If REDHAT-BUG-1390588 is not addressed, unauthorized users may gain access to sensitive configuration information.