Property
Languagehcl
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Redis cache is configured to allow non-SSL (unencrypted) connections, which means data sent between clients and the cache can be intercepted and read in plain text. This exposes sensitive information to potential attackers.

Impact#

If exploited, attackers on the network could eavesdrop on credentials, session data, or other sensitive information transmitted to and from the Redis cache. This can lead to data breaches, unauthorized access, and compromise of confidential data.