Couchbase Alerts

This page lists critical alerts and advisories for Couchbase.

Stay informed about the latest critical alerts and advisories for Couchbase Server by subscribing to our update notifications. To sign up, please register on our support site and follow this article: Announcements – Couchbase Support

Enterprise Security Alerts

  • Credentials are negotiated with KV using SCRAM-SHA when remote link encryption is configured for HALF

    SDK will negotiate with SCRAM-SHA by default which allows for a MITM to negotiate for PLAIN credentials

    Products:

    Couchbase Server

    Impact:

    Medium (5.9)

    Affects Version:

    7.6.0,
    7.2.4,
    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x

    Fix Version:

    7.6.1,
    7.2.5

  • Upgrade to OpenSSL 3.1.4

    Applications that use the functions DH_generate_key() to generate an X9.42 DH key and applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.

    Products:

    Couchbase Server

    Impact:

    Medium (5.3)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix Version:

    7.2.4

  • Upgrade cURL to 8.4.0

    The flaw in curl makes it overflow a heap based buffer in the SOCKS5 proxy handshake.

    Products:

    Couchbase Server

    Impact:

    Critical (9.8)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Fix Version:

    7.2.4

  • TLS Private key leaked in XDCR log file

    The private key used for Cross Datacenter Replication (XDCR) was leaked in the goxdcr.log

    Products:

    Couchbase Server

    Impact:

    Low (2.1)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.5.x

    Fix Version:

    7.2.4

  • The internal Full Admin user for cluster management credentials leaked to log file

    A logging event caused the internal @ns_server admin credentials to be leaked in encoded form in diag.log.

    Products:

    Couchbase Server

    Impact:

    Low (2.1)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.6,
    7.1.5

    Fix Version:

    Server 7.2.4

  • Eventing SQL++ cURL calls to /diag/eval were not sufficiently restricted

    Calling cURL via SQL++ (N1QL) via the Eventing Service to the local host’s /diag/eval endpoint wasn’t fully prevented.

    Products:

    Couchbase Server

    Impact:

    High (8.6)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.5.x

    Fix Version:

    Server 7.2.4

Start building

Check out our developer portal to explore NoSQL, browse resources, and get started with tutorials.

Use Capella free

Get hands-on with Couchbase in just a few clicks. Capella DBaaS is the easiest and fastest way to get started.

Get in touch

Want to learn more about Couchbase offerings? Let us help.