Alertes Couchbase

Cette page répertorie les alertes et avis critiques pour Couchbase.

Restez informé des dernières alertes et avis critiques pour Couchbase Server en vous abonnant à nos notifications de mise à jour. Pour vous inscrire, veuillez vous enregistrer sur notre site de support et suivre cet article : Annonces – Support Couchbase

Alertes de sécurité d'entreprise

  • Update of GoLang to 1.19.9

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Version de correction :

    7.2.1,
    7.1.5

  • Upgrade to OpenSSL 1.1.1u

    A vulnerability in OpenSSL related to the verification of X.509 certificate chains that include policy constraints., which would allow attackers to be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Version de correction :

    7.2.1,
    7.1.5

  • Upgrade Golang to 1.20.10

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Version de correction :

    7.2.3,
    7.1.6

  • Upgrade gRPC to v1.58.3

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    Produits :

    Serveur Couchbase

    Impact

    Élevé (7,5)

    Version affectée :

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    Version de correction :

    7.2.3,
    7.1.6

  • Update Netty to 4.1.86.Final or higher

    In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.

    Produits :

    Serveur Couchbase

    Impact

    Low (2.2)

    Version affectée :

    6.6.6,
    7.0.5,
    7.1.3

    Version de correction :

    7.2.0,
    7.1.4

  • Full Text Search (FTS) nsstats endpoint is accessible without authentication

    The FTS stats endpoint at /api/nsstats does not implement correct authentication, so it is possible to view the names of Couchbase Server buckets, the names of FTS indexes and configuration of FTS indexes without authentication. The contents of the buckets and indexes are not exposed.

    Produits :

    Serveur Couchbase

    Impact

    Moyen (5,3)

    Version affectée :

    7.1.3 – 7.1.0,
    7.0.x,
    6.6.x

    Version de correction :

    7.1.4

Commencer à construire

Consultez notre portail pour développeurs afin d'explorer NoSQL, de parcourir les ressources et de commencer à utiliser les tutoriels.

Utiliser Capella gratuitement

Prenez en main Couchbase en quelques clics. Capella DBaaS est le moyen le plus simple et le plus rapide de démarrer.

Prendre contact

Vous souhaitez en savoir plus sur les offres Couchbase ? Laissez-nous vous aider.