Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Redis instance in Google Cloud Memorystore is not configured with AUTH enabled, meaning it does not require a password for access. This leaves the database open to unauthorized connections.

Impact#

Without AUTH enabled, anyone with network access to the Redis instance can read, modify, or delete data, potentially leading to data breaches, service disruption, or unauthorized manipulation of application data.