This page lists critical alerts and advisories for Couchbase.
CVE | Synopsis | Impact (CVSS) | Products | Affects Version | Fix Version | Publish Date |
---|---|---|---|---|---|---|
Update Netty to 4.1.86.Final or higher. |
Low |
Couchbase Server |
Server |
Server |
May 2023 |
|
Full Text Search (FTS) nsstats endpoint is accessible without authentication. |
Medium |
Couchbase Server |
Server |
Server |
March 2023 |
|
Credentials can be leaked to the logs if there is a crash during a node join. |
Medium |
Couchbase Server |
Server |
Server |
January 2023 |
|
Couchbase Cluster Manager lacks access controls during a cluster node restart. |
Critical |
Couchbase Server |
Server |
Server |
January 2023 |
|
Update of Jackson Databind to 2.13.4.2+ as used in the Analytics Service to resolve vulnerabilities. |
High |
Couchbase Server |
Server |
Server |
January 2023 |
|
A crafted HTTP request to REST API can cause a backup service OOM. |
Medium |
Couchbase Server |
Server |
Server |
January 2023 |
|
Update of V8 Javascript Engine to 10.7.x. |
High |
Couchbase Server |
Server |
Server |
January 2023 |
|
Update of Apache Parquet to 1.12.3. |
High |
Couchbase Server |
Server |
Server |
November 2022 |
|
Upgrade of Erlang to version 24.3.4.4. |
Critical |
Couchbase Server |
Server |
Server |
November 2022 |
|
Private key is leaked to the log files with certain crashes. |
Medium |
Couchbase Server |
Server |
Server |
July 2022 |
|
Update of GoLang to a minimum of 1.17.9 or 1.18.1. |
High |
Couchbase Server |
Server |
Server |
July 2022 |
|
Update of jackson-databind library to version 2.13.2.2. |
Medium |
Couchbase Server |
Server |
Server |
July 2022 |
|
Update of openssl to 1.1.1o. |
Critical |
Couchbase Server |
Server |
Server |
July 2022 |
|
Encrypted Private Key passphrase may be leaked in the logs. |
Medium |
Couchbase Server |
Server |
Server |
July 2022 |
|
Updating ramda, a client-side javascript library to version 0.28 as used in the Couchbase Server UI. |
Critical |
Couchbase Server |
Server |
Server |
July 2022 |
|
Update of js-beautify to 1.14.3, a client-side javascript library used in the Couchbase Server UI. |
Critical |
Couchbase Server |
Server |
Server |
July 2022 |
|
Field names are not redacted in logged validation messages for Analytics Service. |
Low |
Couchbase Server |
Server |
Server |
June 2022 |
|
Analytics Remote Links may temporarily downgrade to non-TLS connection to determine TLS port. |
Low |
Couchbase Server |
Server |
Server |
June 2022 |
|
Backup Service log leaks unredacted usernames and doc ids. |
Low |
Couchbase Server |
Server |
Server |
June 2022 |
|
Update golang.org/x/text package to 0.3.4 or later. |
High |
Couchbase Server |
Server |
Server |
June 2022 |
|
couchbase-cli leaks Secrets Management master password as a command-line argument. |
Medium |
Couchbase Server |
Server |
Server |
June 2022 |
|
Operations may succeed on collection using stale RBAC permission. |
High |
Couchbase Server |
Server |
Server |
June 2022 |
|
XDCR - lacks role checking when changing internal settings. |