Alertes Couchbase

Cette page répertorie les alertes et avis critiques pour Couchbase.

Restez informé des dernières alertes et avis critiques pour Couchbase Server en vous abonnant à nos notifications de mise à jour. Pour vous inscrire, veuillez vous enregistrer sur notre site de support et suivre cet article : Annonces – Support Couchbase

Alertes de sécurité d'entreprise

  • Update golang.org/x/text package to 0.3.4 or later

    The golang.org/x/text/encoding/unicode package which could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x

    Version de correction :

    7.0.4,
    6.6.6

  • Backup Service log leaks unredacted usernames and doc ids

    If the backup service fails to log an audit message, it leaks the audit log data into the backup_service.log which isn’t redacted.

    Produits :

    Serveur Couchbase

    Impact

    Low (1.8)

    Version affectée :

    7.0.x

    Version de correction :

    7.1.0

  • Analytics Remote Links may temporarily downgrade to non-TLS connection to determine TLS port

    On failure to establish TLS connection for an Analytics Remote Link configured with encryption=full, the runtime would attempt to discover the (non-default) TLS port by attempting a non-TLS connection to the remote cluster, using SCRAM-SHA for authentication. While credentials are not shared when SCRAM-SHA, it may not be expected that the system would downgrade the prescribed encryption level which specified a TLS connection. This fallback mechanism has been removed, and in a failure to initially establish a TLS connection, the CONNECT LINK will simply fail until the correct TLS port is provided as part of the link configuration.

    Produits :

    Serveur Couchbase

    Impact

    Low (2.0)

    Version affectée :

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0

    Version de correction :

    7.0.4,
    6.6.6

  • Field names are not redacted in logged validation messages for Analytics Service

    When creating secondary indexes with the Couchbase Server Analytics Service, there are some validations on the indexed fields which are reported to the user and logged. The error message with code ASX0013 is used in multiple paths to report and log that there is a duplicate field name. The field names in these logged validation messages are not redacted. Also errors with the code ASX1079 has field names which are not redacted.

    Produits :

    Serveur Couchbase

    Impact

    Low (1.8)

    Version affectée :

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    Version de correction :

    7.0.4,
    6.6.6

  • Untrusted node addition can be manipulated in order to harvest a cluster secret

    Administrators adding an untrusted node to a cluster could inadvertently risk transmitting the cluster cookie which should remain secret. This can be addressed by deploying TLS encryption with Certificate Authority signed certificates. When using TLS, a trusted certificate is required to be present on the incoming node from Couchbase Server version 7.1.0. Reconnaissance Ofir Hamam, security researcher at EY Israel’s Advanced Security Center

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,6)

    Version affectée :

    7.0.3 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Version de correction :

    7.1.0

  • Secrets not redacted in logs collected from Kubernetes environments

    Couchbase Operator 2.2.0 introduced an optimization that simplified log collection. When logs are collected, the support tool – “cbopinfo” – is used to collect Kubernetes resources necessary to gain insight into intended resource state, and current resource status. Prior to the affected versions, secret data was redacted, however this functionality was not retained in the new collection method. As a result, logs would have erroneously contained any passwords, tokens, and private keys within the scope of the log collection. By default, this scope will be limited to the Kubernetes namespace in which the Couchbase Server cluster under inspection resides. The exception to this is if the –system flag was specified, in which case all secrets on the platform will have been exposed. Logs are used to identify and remediate customer issues, and therefore only customers that have supplied logs, with the specified tool versions, are affected. Couchbase will ensure that all affected logs which have been provided are redacted.

    Produits :

    Couchbase Cloud Native Operator

    Impact

    High (7.2)

    Version affectée :

    2.2.0,
    2.2.1,
    2.2.2

    Version de correction :

    2.2.3

Commencer à construire

Consultez notre portail pour développeurs afin d'explorer NoSQL, de parcourir les ressources et de commencer à utiliser les tutoriels.

Utiliser Capella gratuitement

Prenez en main Couchbase en quelques clics. Capella DBaaS est le moyen le plus simple et le plus rapide de démarrer.

Prendre contact

Vous souhaitez en savoir plus sur les offres Couchbase ? Laissez-nous vous aider.