lacework-global-391
ElastiCache for Redis cache clusters should have auto minor version upgrade enabled (Automated)
Description
AutoMinorVersionUpgrade is a feature that you can turn on in ElastiCache for Redis to have your cache clusters automatically upgraded when a new minor cache engine version is available.
These upgrades might include security patches and bug fixes. Staying up-to-date with patch installation is an important step in securing systems.
Remediation
From the AWS Console:
- Log in to the AWS Management Console.
- Click Services.
- Select Database > ElastiCache.
- Under Resources, click Redis caches.
- For the cache of interest, select it and click Actions > Modify.
- Under Maintenance, select Enable for Auto upgrade minor versions.
- Once finished, click Preview changes.
- Under Schedule modifications, select Yes for Apply immediately, and click Modify.
From CLI:
aws elasticache modify-cache-cluster --cache-cluster-id <cluster_id> --auto-minor-version-upgrade --apply-immediately
References
https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-2
https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/VersionManagement.html