Alertas de Couchbase

Esta página enumera alertas y avisos críticos para Couchbase.

Manténgase informado sobre las últimas alertas críticas y avisos para Couchbase Server suscribiéndose a nuestras notificaciones de actualización. Para suscribirse, regístrese en nuestro sitio de soporte y siga este artículo: Anuncios – Soporte de Couchbase

Alertas de Seguridad Empresarial

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Productos:

    Servidor Couchbase

    Impacto

    High (8.2)

    Versión que afecta:

    7.0.0 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Versión de la corrección:

    6.6.3,
    7.0.1

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Productos:

    Servidor Couchbase

    Impacto

    High (8.2)

    Versión que afecta:

    7.0.0,
    6.6.2 – 6.6.0,
    6.5.x

    Versión de la corrección:

    6.6.3,
    7.0.1

  • Update of AngularJS to 1.8.0

    Issue in Angular as used by the Couchbase UI that can cause a denial of service by modifying the merge() function.

    Productos:

    Servidor Couchbase

    Impacto

    Alta (7.5)

    Versión que afecta:

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Versión de la corrección:

    6.6.3

  • Update of OpenSSL to version 1.1.1k

    Multiple security issues resolved in OpenSSL, one of which could cause the TLS server to crash if sent a maliciously crafted renegotiation ClientHello message from a client.

    Productos:

    Servidor Couchbase

    Impacto

    Medium / High (5.9, 7.4, 7.5)

    Versión que afecta:

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x

    Versión de la corrección:

    6.6.3

  • Externally managed users are not prevented from using an empty password, per RFC4513

    If an LDAP or Active Directory server, used for external authentication, is configured to allow insecure unauthenticated binds, the Couchbase Server Cluster Manager will allow an external user to be authenticated with an empty password. LDAP servers can be configured to fail Unauthenticated Bind requests with a resultCode of “unwillingToPerform” to prevent this occurring.

    Productos:

    Servidor Couchbase

    Impacto

    Crítico (9.8)

    Versión que afecta:

    6.6.2 – 6.6.0,
    6.5.x

    Versión de la corrección:

    6.6.3

  • Index Service is leaking internal administrative credentials into the logging.

    Internal rest calls (/listCreateTokens, /listRebalanceTokens, /listMetadataTokens) are getting logged into the indexer.log with unredacted Base64 encoded authentication information for internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth.

    Productos:

    Servidor Couchbase

    Impacto

    Crítico (9.8)

    Versión que afecta:

    6.6.1,
    6.6.0,
    6.5.1,
    6.5.0,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    Versión de la corrección:

    6.6.2,
    6.5.2

Empezar a construir

Consulte nuestro portal para desarrolladores para explorar NoSQL, buscar recursos y empezar con tutoriales.

Utilizar Capella gratis

Ponte manos a la obra con Couchbase en unos pocos clics. Capella DBaaS es la forma más fácil y rápida de empezar.

Póngase en contacto

¿Quieres saber más sobre las ofertas de Couchbase? Permítanos ayudarle.