Alertes Couchbase

Cette page répertorie les alertes et avis critiques pour Couchbase.

Restez informé des dernières alertes et avis critiques pour Couchbase Server en vous abonnant à nos notifications de mise à jour. Pour vous inscrire, veuillez vous enregistrer sur notre site de support et suivre cet article : Annonces – Support Couchbase

Alertes de sécurité d'entreprise

  • SQL++ N1QL cURL host restrictions implementation issue

    The SQL++ (N1QL) cURL allowlist protection in the Query Service, wasn’t sufficient in preventing accessing restricted hosts.

    Produits :

    Serveur Couchbase

    Impact

    Moyen (5,3)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x

    Version de correction :

    7.2.4

  • SQL++ cURL calls to /diag/eval were not sufficiently restricted

    Calling cURL via SQL++ (N1QL) using the Query Service to the localhost’s /diag/eval endpoint wasn’t fully prevented.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (8,6)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x

    Version de correction :

    7.2.4

  • otpCookie was shown to a user with a Full Admin role on the Cluster Manager’s API endpoints serverGroups and engageCluster2

    The cluster’s otpCookie was leaked to users with Full Admin role on API endpoint serverGroups and both Cluster Admin and Full Admin on API endpoint engageCluster2. This could be used to elevate privileges

    Produits :

    Serveur Couchbase

    Impact

    Élevé (8,6)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Version de correction :

    7.2.4

  • Unauthenticated RMI Service Ports Exposed in Analytics Service

    Network ports 9119 and 9121 were unauthenticated RMI service ports hosted by the Analytics Service which could result in privilege escalation.

    Produits :

    Serveur Couchbase

    Impact

    Critical (9.1)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x

    Version de correction :

    Serveur 7.2.4

  • Data readers could DOS the reader threads

    A user with Data Reader role could lock a Data Service reader thread for a significant time by requesting a high number of keys and potentially lock up all reader threads by issuing the same command on multiple connections

    Produits :

    Serveur Couchbase

    Impact

    Medium (4.3)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Version de correction :

    Serveur 7.2.4

  • User with Data Reader role could OOM kill the Data Service

    A user with the Data Reader privilege could kill the Data Service by sending GetKeys requesting a high number of documents, triggering a Out-of-Memory (OOM) error.

    Produits :

    Serveur Couchbase

    Impact

    Moyen (6,5)

    Version affectée :

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Version de correction :

    Serveur 7.2.4

Commencer à construire

Consultez notre portail pour développeurs afin d'explorer NoSQL, de parcourir les ressources et de commencer à utiliser les tutoriels.

Utiliser Capella gratuitement

Prenez en main Couchbase en quelques clics. Capella DBaaS est le moyen le plus simple et le plus rapide de démarrer.

Prendre contact

Vous souhaitez en savoir plus sur les offres Couchbase ? Laissez-nous vous aider.