Couchbase-Warnungen

Diese Seite listet kritische Alerts und Advisories für Couchbase auf.

Bleiben Sie auf dem Laufenden über die neuesten kritischen Alerts und Advisories für Couchbase Server, indem Sie sich für unsere Update-Benachrichtigungen anmelden. Um sich anzumelden, registrieren Sie sich bitte auf unserer Support-Seite und folgen Sie diesem Artikel: Ankündigungen – Couchbase Support

Unternehmenssicherheitswarnungen

  • Update of V8 Javascript Engine to 10.7.x

    The v8 Javascript engine as used in the Couchbase Server Eventing Service, View Engine, XDCR and N1QL UDFs has been updated as there’s a type confusion in versions prior to 99.0.4844.84 which allowed a remote attacker to potentially exploit heap corruption via a crafted request.

    Produkte

    Couchbase Server

    Auswirkung:

    Hoch (8,8)

    Betrifft Version:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix-Version:

    7.1.2,
    7.0.5

  • A crafted HTTP request to REST API can cause a backup service OOM

    An extremely large (or unbounded) HTTP request body may cause the backup service to cause an OOM (out-of-memory) error.

    Produkte

    Couchbase Server

    Auswirkung:

    Mittel (4,9)

    Betrifft Version:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0

    Fix-Version:

    7.1.2,
    7.0.5

  • Update of Jackson Databind to 2.13.4.2+ as used in the Analytics Service to resolve vulnerabilities

    A resource exhaustion of the Couchbase Analytics Service can occur because of a lack of a check to prevent use of deeply nested arrays.

    Produkte

    Couchbase Server

    Auswirkung:

    Hoch (7,5)

    Betrifft Version:

    7.1.2 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x

    Fix-Version:

    7.1.3,
    7.0.5,
    6.6.6

  • Couchbase Cluster Manager lacks access controls during a cluster node restart

    During the start of a couchbase server node there is a short time period where the security cookie is set to “nocookie” which lacks access controls over the Erlang distribution protocol. If an attacker connects to this protocol during this period, they can execute arbitrary code remotely on any cluster node at any point of time until their connection is dropped. The executed code will be running with the same privileges as the Couchbase Server.

    Produkte

    Couchbase Server

    Auswirkung:

    Kritisch (9,8)

    Betrifft Version:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    Fix-Version:

    7.1.2,
    7.0.5,
    6.6.6

  • Credentials can be leaked to the logs if there is a crash during a node join.

    During a node join failure, unredacted credentials of the user making the REST request can be leaked into the log files.

    Produkte

    Couchbase Server

    Auswirkung:

    Medium (6.3)

    Betrifft Version:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x,
    3.x,
    2.x

    Fix-Version:

    7.1.2,
    7.0.5,
    6.6.6

  • Upgrade of Erlang to version 24.3.4.4

    When using the tls/ssl feature in couchbase server, it is possible to bypass client authentication in certain situations. Specifically, any application using the ssl/tls/dtls server, and the client certification option “{verify, verify_peer}” are affected by this vulnerability. Corrections have been released on the supported tracks with patches 23.3.4.15, 24.3.4.2, and 25.0.2 of the erlang/OTP runtime. Only clusters using certificate-based authentication are affected.

    Produkte

    Couchbase Server

    Auswirkung:

    Kritisch (9,8)

    Betrifft Version:

    7.1.1,
    7.1.0

    Fix-Version:

    7.1.2

Mit dem Bau beginnen

Besuchen Sie unser Entwicklerportal, um NoSQL zu erkunden, Ressourcen zu durchsuchen und mit Tutorials zu beginnen.

Capella kostenlos nutzen

Mit nur wenigen Klicks können Sie Couchbase in die Praxis umsetzen. Capella DBaaS ist der einfachste und schnellste Weg, um loszulegen.

Kontakt aufnehmen

Möchten Sie mehr über das Angebot von Couchbase erfahren? Wir helfen Ihnen gerne.