[CRITICAL] Valkey (Redis) exposed on mesh network without authentication #13
Labels
No labels
area:documentation
area:infrastructure
area:network
area:security
priority:critical
priority:high
priority:low
priority:medium
status:blocked
type:bug
type:deployment
type:enhancement
type:investigation
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
reinitialized.net/infrastructure#13
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Labels:
area:security,area:containers,priority:critical,type:bugDescription
The Valkey container on db1 binds to
10.255.0.11:1025without any authentication configured. There is norequirepassdirective or ACL configuration.File:
hosts/db1.nixlines 173-186Impact
CRITICAL — Any host on the mesh network (10.255.0.0/24) can connect to Valkey and:
Services depending on this Valkey instance: Authentik, Pelican Panel, Paperless-ngx.
Recommended Fix
requirepasswith a strong password to Valkey configuration