Redis server does not require authentication to gain access

IT scanning detected this vulnerability of “high” severity. Our cryosparc version is already the latest 5.0.7 but the Redis version it comes with is 7.4.0 which has at least 6 vulnerabilities. Latest Redis version is 7.4.10

What is the suggested remediation? Can the “protected-mode” be turned to yes?

Thanks @istv01 for reporting. A fix will be included in a future software release. Please ensure that the CryoSPARC instance is operated in a private and trusted network.