gcp-memorystore-cluster-acl-rule

A Redis Cluster ACL rule is readable plaintext and its rule string can include a cleartext password introduced with the Redis ACL >password syntax.

gcpcritical service: gcp:memorystore emits CanReadCredential

Where it sits

locationredis.projects.locations.aclPolicies.get.rules[].{username,rule}
location kindpolicy_document
data kindspassword credential pii sensitive_data
emits edgeCanReadCredential
serviceMemorystore (gcp:memorystore)

Collection recipe

access moderead_api
operationredis.projects.locations.aclPolicies.get
response pathrules[].{username,rule}
encodinglist
params{"name": "\u003cresource-name\u003e"}

Required permissions

redis.aclPolicies.get

References

move · open · esc close