Redis unauthorized access vulnerability

Updated at:
Copy as MD

A guide to fixing the Redis unauthorized access vulnerability.

Threat description

If a Redis server lacks proper identity verification and access control, an attacker can read all data stored in Redis, including sensitive information. The attacker can also combine this vulnerability with others to execute code and control the server.

Vulnerability details: https://avd.aliyun.com/detail/AVD-02021-0344

Remediation

1. Set an access password. In the redis.conf configuration file, uncomment the `requirepass` parameter and set a strong password. Your password should be long and contain a mix of uppercase letters, lowercase letters, numbers, and special characters. Save the file and restart the Redis service.

2. Restrict external access (Optional).

  • Restrict the listener IP address. In the `redis.conf` configuration file, set the `bind` parameter to the local address (127.0.0.1) or a specific trusted IP address.

  • Configure whitelists and ECS security groups. For more information, see Configure IP whitelists.

If you encounter any issues during this process or have other questions, go to Security Center and click "Need Security Help" to contact a technical engineer for support.