Couchbase Alerts

This page lists critical alerts and advisories for Couchbase.

Stay informed about the latest critical alerts and advisories for Couchbase Server by subscribing to our update notifications. To sign up, please register on our support site and follow this article: Announcements – Couchbase Support

Enterprise Security Alerts

  • Update of GoLang to 1.19.9

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Fix Version:

    7.2.1,
    7.1.5

  • Upgrade to OpenSSL 1.1.1u

    A vulnerability in OpenSSL related to the verification of X.509 certificate chains that include policy constraints., which would allow attackers to be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix Version:

    7.2.1,
    7.1.5

  • Upgrade Golang to 1.20.10

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Fix Version:

    7.2.3,
    7.1.6

  • Upgrade gRPC to v1.58.3

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    Products:

    Couchbase Server

    Impact:

    High (7.5)

    Affects Version:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Fix Version:

    7.2.3,
    7.1.6

  • Update Netty to 4.1.86.Final or higher

    In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.

    Products:

    Couchbase Server

    Impact:

    Low (2.2)

    Affects Version:

    6.6.6,
    7.0.5,
    7.1.3

    Fix Version:

    7.2.0,
    7.1.4

  • Full Text Search (FTS) nsstats endpoint is accessible without authentication

    The FTS stats endpoint at /api/nsstats does not implement correct authentication, so it is possible to view the names of Couchbase Server buckets, the names of FTS indexes and configuration of FTS indexes without authentication. The contents of the buckets and indexes are not exposed.

    Products:

    Couchbase Server

    Impact:

    Medium (5.3)

    Affects Version:

    7.1.3 – 7.1.0,
    7.0.x,
    6.6.x

    Fix Version:

    7.1.4

Start building

Check out our developer portal to explore NoSQL, browse resources, and get started with tutorials.

Use Capella free

Get hands-on with Couchbase in just a few clicks. Capella DBaaS is the easiest and fastest way to get started.

Get in touch

Want to learn more about Couchbase offerings? Let us help.