Skip to content

Redis Exporter Exposed Detection

redis-exporter-exposed is a medium severity check in the monitoring category, written in yaml. Its source is templates/monitoring/exporters/redis/redis-exporter-exposed.yaml in cert-x-gen-templates.

Detects publicly exposed Redis exporters (Prometheus exporters for Redis). Redis exporters expose internal Redis metrics and statistics that can reveal sensitive information about the Redis instance, including version, memory usage, connected clients, and replication status.

This template tests HTTP/HTTPS endpoints commonly used by Redis exporters. For direct Redis protocol testing, use the ‘redis-unauthenticated-access’ template.

PROTOCOL FLEXIBILITY:

  • Uses ‘http:’ section for HTTP/HTTPS testing
  • Engine automatically detects supported protocols: HTTP and HTTPS
  • Recommended ports: 9121 (redis_exporter), 9090 (Prometheus), 9100 (node_exporter)
Field Value
Id redis-exporter-exposed
Severity medium
Language yaml
Category monitoring
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 90
CVSS not recorded
Weakness CWE-200
Tags redis, exporter, prometheus, metrics, exposure, monitoring, http
Target kind not recorded
Oracle not recorded

The file declares extractors, http, remediation as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info redis-exporter-exposed

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.