Hi Team,
We have newly deployed UX NextGen in a customer environment, and vulnerability scanning has reported a critical finding.
Vulnerability Details
- Vulnerability Name: Redis Server Without Password Authentication (Plugin ID: 100634)
- Risk Level: Critical
- CVSS v3 Score: 9.8
- Affected Port: 6379
- Installed Redis Version: 8.8.0
- Description: The Redis server has no password‑based authentication enabled. Unauthenticated clients can retrieve server information via INFO commands, exposing an unauthorised‑access risk.
Could you please advise whether it is supported to set a password for Redis in this UX NextGen deployment?
If supported, kindly share the detailed procedure and the exact configuration files that require modification.
If password configuration is not available in the current release, can I submit a feature request to add Redis password support and related configuration options in future versions?
Thanks,
Finch