Couchbase Alerts

This page lists critical alerts and advisories for Couchbase.

Stay informed about the latest critical alerts and advisories for Couchbase Server by subscribing to our update notifications. To sign up, please register on our support site and follow this article: Announcements – Couchbase Support

Enterprise Security Alerts

  • Query Service stats endpoint was accessible without authentication

    The Query stats endpoint did not implement correct authentication, making it possible to view the stats information

    Products:

    Couchbase Server

    Impact:

    Medium (5.3)

    Affects Version:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x

    Fix Version:

    7.2.4

  • Private key leak in debug.log while adding pre-7.0 node to 7.2 cluster

    The private key is leaked to debug.log when adding a pre-7.0 node to 7.2 cluster.

    Products:

    Couchbase Server

    Impact:

    Medium (4.4)

    Affects Version:

    7.2.0

    Fix Version:

    7.2.1

  • Unauthenticated users may cause memcached to run out of memory

    A malicious user may easily crash a memcached server by connecting to the server and start sending large commands.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    Fix Version:

    7.2.1,
    7.1.5

  • Windows traversal security issue

    The Couchbase Server Windows UI allows an attacker to traverse the filesystem and display files that Couchbase has access to. This vulnerability doesn’t require any authentication. It’s exploitable with just appending folders/files to the Couchbase Server admin UI’s URL.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix Version:

    7.2.1,
    7.1.5

  • Update OpenJDK to 11.0.19

    Update OpenJDK to versions 11.0.19 to resolve numerous CVEs.

    Products:

    Couchbase Server

    Impact:

    High (7.4)

    Affects Version:

    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    Fix Version:

    7.1.5

  • Update V8 to 11.4.185.1

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Products:

    Couchbase Server

    Impact:

    High (8.0)

    Affects Version:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix Version:

    7.2.1,
    7.1.5

Start building

Check out our developer portal to explore NoSQL, browse resources, and get started with tutorials.

Use Capella free

Get hands-on with Couchbase in just a few clicks. Capella DBaaS is the easiest and fastest way to get started.

Get in touch

Want to learn more about Couchbase offerings? Let us help.