Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • Update of Apache Log4J to 2.15.0

    A critical issue in the Apache Log4J utility as used by the Couchbase Analytics Service requires updating to prevent potential Remote Code Execution (RCE) and sensitive data extraction.

    Prodotti:

    Couchbase Server

    Impatto

    Critical (10)

    Versioni interessate:

    7.0.2 – 7.0.0,
    6.6.3 – 6.6.0,
    6.5.x,
    6.0.x

    Versione di correzione:

    7.0.3,
    6.6.4

  • Update of the Python cryptography package to 3.3.2

    In the cryptography package before 3.3.2 for Python, as used by the Couchbase Server command line tools, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow in that tool.

    Prodotti:

    Couchbase Server

    Impatto

    Critical (9.1)

    Versioni interessate:

    7.0.1,
    7.0.0,
    6.6.2 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.5.x

    Versione di correzione:

    6.6.3,
    7.0.2

  • Update of the Python urllib3 to 1.26.5 or higher

    An issue was discovered in urllib3 before 1.26.5, as used by Couchbase Server command line tools. When these tools are provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service of the command line tool if a URL were passed as a parameter or redirected to via an HTTP redirect.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.0.1,
    7.0.0,
    6.6.2 – 6.6.0,
    6.5.x,
    6.0.x

    Versione di correzione:

    6.6.3,
    7.0.2

  • Credentials exposed in crash error log from a backtrace

    As part of a cbcollect_info log collection, Couchbase Server collects the process info of all the processes running in the Erlang VM. The issue occurs when the cluster manager forwards an HTTP request from the pluggable UI (query workbench, etc.) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the “@” user credentials of the node processing the UI request. For the issue to occur, the process info has to be triggered at the exact moment when a pluggable UI request is being serviced by the cluster manager.

    Prodotti:

    Couchbase Server

    Impatto

    High (8.8)

    Versioni interessate:

    7.0.1 – 7.0.0,
    6.6.2 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.5.x

    Versione di correzione:

    6.6.3,
    7.0.2

  • Logs not redacting XDCR remoteCluster credentials

    Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.6)

    Versioni interessate:

    7.0.1,
    7.0.0

    Versione di correzione:

    7.0.2

  • Sync Gateway insecurely stores Couchbase Server bucket credentials

    The bucket credentials used by Sync Gateway to read and write data in Couchbase Server was insecurely being stored in the metadata within sync documents written to the bucket. Users with read access could use these credentials to obtain write access. This issue does not affect clusters where Sync Gateway is authenticated with x.509 client certificates. This issue also does not affect clusters where shared bucket access is not enabled on Sync Gateway.

    Prodotti:

    Gateway di sincronizzazione Couchbase

    Impatto

    Medio (6,5)

    Versioni interessate:

    2.8.2 – 2.8.0,
    2.8.1,
    2.7.x

    Versione di correzione:

    2.8.3

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.