Couchbase Alerts

This page lists critical alerts and advisories for Couchbase.

Stay informed about the latest critical alerts and advisories for Couchbase Server by subscribing to our update notifications. To sign up, please register on our support site and follow this article: Announcements – Couchbase Support

Enterprise Security Alerts

  • Update golang.org/x/text package to 0.3.4 or later

    The golang.org/x/text/encoding/unicode package which could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x

    Fix Version:

    7.0.4,
    6.6.6

  • Backup Service log leaks unredacted usernames and doc ids

    If the backup service fails to log an audit message, it leaks the audit log data into the backup_service.log which isn’t redacted.

    Products:

    Couchbase Server

    Impact:

    Low (1.8)

    Affects Version:

    7.0.x

    Fix Version:

    7.1.0

  • Analytics Remote Links may temporarily downgrade to non-TLS connection to determine TLS port

    On failure to establish TLS connection for an Analytics Remote Link configured with encryption=full, the runtime would attempt to discover the (non-default) TLS port by attempting a non-TLS connection to the remote cluster, using SCRAM-SHA for authentication. While credentials are not shared when SCRAM-SHA, it may not be expected that the system would downgrade the prescribed encryption level which specified a TLS connection. This fallback mechanism has been removed, and in a failure to initially establish a TLS connection, the CONNECT LINK will simply fail until the correct TLS port is provided as part of the link configuration.

    Products:

    Couchbase Server

    Impact:

    Low (2.0)

    Affects Version:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0

    Fix Version:

    7.0.4,
    6.6.6

  • Field names are not redacted in logged validation messages for Analytics Service

    When creating secondary indexes with the Couchbase Server Analytics Service, there are some validations on the indexed fields which are reported to the user and logged. The error message with code ASX0013 is used in multiple paths to report and log that there is a duplicate field name. The field names in these logged validation messages are not redacted. Also errors with the code ASX1079 has field names which are not redacted.

    Products:

    Couchbase Server

    Impact:

    Low (1.8)

    Affects Version:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    Fix Version:

    7.0.4,
    6.6.6

  • Untrusted node addition can be manipulated in order to harvest a cluster secret

    Administrators adding an untrusted node to a cluster could inadvertently risk transmitting the cluster cookie which should remain secret. This can be addressed by deploying TLS encryption with Certificate Authority signed certificates. When using TLS, a trusted certificate is required to be present on the incoming node from Couchbase Server version 7.1.0. Recognition: Ofir Hamam, security researcher at EY Israel’s Advanced Security Center

    Products:

    Couchbase Server

    Impact:

    High (7.6)

    Affects Version:

    7.0.3 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix Version:

    7.1.0

  • Secrets not redacted in logs collected from Kubernetes environments

    Couchbase Operator 2.2.0 introduced an optimization that simplified log collection. When logs are collected, the support tool – “cbopinfo” – is used to collect Kubernetes resources necessary to gain insight into intended resource state, and current resource status. Prior to the affected versions, secret data was redacted, however this functionality was not retained in the new collection method. As a result, logs would have erroneously contained any passwords, tokens, and private keys within the scope of the log collection. By default, this scope will be limited to the Kubernetes namespace in which the Couchbase Server cluster under inspection resides. The exception to this is if the –system flag was specified, in which case all secrets on the platform will have been exposed. Logs are used to identify and remediate customer issues, and therefore only customers that have supplied logs, with the specified tool versions, are affected. Couchbase will ensure that all affected logs which have been provided are redacted.

    Products:

    Couchbase Cloud Native Operator

    Impact:

    High (7.2)

    Affects Version:

    2.2.0,
    2.2.1,
    2.2.2

    Fix Version:

    2.2.3

Start building

Check out our developer portal to explore NoSQL, browse resources, and get started with tutorials.

Use Capella free

Get hands-on with Couchbase in just a few clicks. Capella DBaaS is the easiest and fastest way to get started.

Get in touch

Want to learn more about Couchbase offerings? Let us help.