Alertes Couchbase

Cette page répertorie les alertes et avis critiques pour Couchbase.

Restez informé des dernières alertes et avis critiques pour Couchbase Server en vous abonnant à nos notifications de mise à jour. Pour vous inscrire, veuillez vous enregistrer sur notre site de support et suivre cet article : Annonces – Support Couchbase

Alertes de sécurité d'entreprise

  • N1QL Common Table Expressions (CTEs) handled access control incorrectly

    Common Table Expression N1QL queries did not correctly honor RBAC security controls, giving read-access to users that did not have the required authorization.

    Produits :

    Serveur Couchbase

    Impact

    Moyen (6,5)

    Version affectée :

    6.6.1,
    6.6.0,
    6.5.2,
    6.5.1,
    6.5.0

    Version de correction :

    6.6.2

  • An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and stats.log files.

    Take care to manually redact any logs exported from the cluster on versions affected by this issue. Upgrading the cluster will automatically prevent the @ns_server password appearing in future log entries.

    Produits :

    Serveur Couchbase

    Impact

    Critical (9.6)

    Version affectée :

    6.6.0,
    6.5.1,
    6.5.0,
    6.0.4,
    5.5.0

    Version de correction :

    6.0.5,
    6.5.2,
    6.6.1

  • Exposed Erlang cookie could lead to Remote Command Execution (RCE) attack.

    Communication between Erlang nodes is done by exchanging a shared secret (aka “magic cookie”). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS-level commands on the system running the Erlang node. Reconnaissance Ofir Hamam, security researcher at EY Israel’s Advanced Security Center

    Produits :

    Serveur Couchbase

    Impact

    High (8.0)

    Version affectée :

    6.5.1

    Version de correction :

    6.6.0

  • Couchbase Server returns a WWW-Authenticate response to unauthenticated requests.

    The Server REST API responds with a {{WWW-Authenticate}} header to unauthenticated requests which allows the user to authenticate via a user / password dialog in a web browser. The problem is that these credentials are cached by the browser which allows a hacker to use CSRF to attack a cluster in the event that an administrator has used their browser to check the results of a REST API request. This behavior can be disabled by using couchbase-cli (couchbase-cli setting-security –set –disable-www-authenticate 1 -c localhost:8091 -u -p ). This is not disabled by default as it might break existing tools or scripts. Reconnaissance Équipe de sécurité d'Apple

    Produits :

    Serveur Couchbase

    Impact

    Medium (6.3)

    Version affectée :

    6.0.0

    Version de correction :

    6.5.1

  • The Cluster Management and Views endpoints are vulnerable to the “Slowloris” denial-of-service attack as they don’t more aggressively terminate slow connections.

    The Slowloris is a type of denial-of-service attack that allows an attacker to take down a target web endpoint by sending requests that periodically send additional headers and never terminate. Reducing the timeout on receipt of HTTP headers is an effective mitigation of this attack and this is the approach taken in the cluster management and views REST endpoints.

    Produits :

    Couchbase Server,
    Couchbase Sync Gateway

    Impact

    Élevé (7,5)

    Version affectée :

    Server 6.5.0,
    Server 6.0.3,
    Sync Gateway < 2.7.0

    Version de correction :

    Server 6.5.1,
    Server 6.0.4

  • FTS UI to upgrade to angular 1.6.9

    The Full Text Seach user interface uses AngularJS 1.4.7 for which some known high severity security vulnerabilities exist. These AngularJS libraries have been updated to a more recent version of Angular which has addressed these vulnerabilities.

    Produits :

    Serveur Couchbase

    Impact

    High (7.4)

    Version affectée :

    6.0.2,
    5.5.5

    Version de correction :

    6.5.0

Commencer à construire

Consultez notre portail pour développeurs afin d'explorer NoSQL, de parcourir les ressources et de commencer à utiliser les tutoriels.

Utiliser Capella gratuitement

Prenez en main Couchbase en quelques clics. Capella DBaaS est le moyen le plus simple et le plus rapide de démarrer.

Prendre contact

Vous souhaitez en savoir plus sur les offres Couchbase ? Laissez-nous vous aider.