Alertes Couchbase

Cette page répertorie les alertes et avis critiques pour Couchbase.

Restez informé des dernières alertes et avis critiques pour Couchbase Server en vous abonnant à nos notifications de mise à jour. Pour vous inscrire, veuillez vous enregistrer sur notre site de support et suivre cet article : Annonces – Support Couchbase

Alertes de sécurité d'entreprise

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Produits :

    Serveur Couchbase

    Impact

    High (8.2)

    Version affectée :

    7.0.0 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Version de correction :

    6.6.3,
    7.0.1

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Produits :

    Serveur Couchbase

    Impact

    High (8.2)

    Version affectée :

    7.0.0,
    6.6.2 – 6.6.0,
    6.5.x

    Version de correction :

    6.6.3,
    7.0.1

  • Update of AngularJS to 1.8.0

    Issue in Angular as used by the Couchbase UI that can cause a denial of service by modifying the merge() function.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Version de correction :

    6.6.3

  • Update of OpenSSL to version 1.1.1k

    Multiple security issues resolved in OpenSSL, one of which could cause the TLS server to crash if sent a maliciously crafted renegotiation ClientHello message from a client.

    Produits :

    Serveur Couchbase

    Impact

    Medium / High (5.9, 7.4, 7.5)

    Version affectée :

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x

    Version de correction :

    6.6.3

  • Externally managed users are not prevented from using an empty password, per RFC4513

    If an LDAP or Active Directory server, used for external authentication, is configured to allow insecure unauthenticated binds, the Couchbase Server Cluster Manager will allow an external user to be authenticated with an empty password. LDAP servers can be configured to fail Unauthenticated Bind requests with a resultCode of “unwillingToPerform” to prevent this occurring.

    Produits :

    Serveur Couchbase

    Impact

    Critique (9.8)

    Version affectée :

    6.6.2 – 6.6.0,
    6.5.x

    Version de correction :

    6.6.3

  • Index Service is leaking internal administrative credentials into the logging.

    Internal rest calls (/listCreateTokens, /listRebalanceTokens, /listMetadataTokens) are getting logged into the indexer.log with unredacted Base64 encoded authentication information for internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth.

    Produits :

    Serveur Couchbase

    Impact

    Critique (9.8)

    Version affectée :

    6.6.1,
    6.6.0,
    6.5.1,
    6.5.0,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    Version de correction :

    6.6.2,
    6.5.2

Commencer à construire

Consultez notre portail pour développeurs afin d'explorer NoSQL, de parcourir les ressources et de commencer à utiliser les tutoriels.

Utiliser Capella gratuitement

Prenez en main Couchbase en quelques clics. Capella DBaaS est le moyen le plus simple et le plus rapide de démarrer.

Prendre contact

Vous souhaitez en savoir plus sur les offres Couchbase ? Laissez-nous vous aider.