Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Prodotti:

    Couchbase Server

    Impatto

    Alto (8,2)

    Versioni interessate:

    7.0.0 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Versione di correzione:

    6.6.3,
    7.0.1

  • A specially crafted network packet sent from an attacker can crash memcached

    This can cause unavailability of the Data Service. It is recommended to use a firewall to only allow network traffic from your applications to communicate with the Couchbase Server cluster.

    Prodotti:

    Couchbase Server

    Impatto

    Alto (8,2)

    Versioni interessate:

    7.0.0,
    6.6.2 – 6.6.0,
    6.5.x

    Versione di correzione:

    6.6.3,
    7.0.1

  • Update of AngularJS to 1.8.0

    Issue in Angular as used by the Couchbase UI that can cause a denial of service by modifying the merge() function.

    Prodotti:

    Couchbase Server

    Impatto

    Alto (7,5)

    Versioni interessate:

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.6.x,
    4.5.x

    Versione di correzione:

    6.6.3

  • Update of OpenSSL to version 1.1.1k

    Multiple security issues resolved in OpenSSL, one of which could cause the TLS server to crash if sent a maliciously crafted renegotiation ClientHello message from a client.

    Prodotti:

    Couchbase Server

    Impatto

    Medium / High (5.9, 7.4, 7.5)

    Versioni interessate:

    6.6.2,
    6.6.1,
    6.6.0,
    6.5.x

    Versione di correzione:

    6.6.3

  • Externally managed users are not prevented from using an empty password, per RFC4513

    If an LDAP or Active Directory server, used for external authentication, is configured to allow insecure unauthenticated binds, the Couchbase Server Cluster Manager will allow an external user to be authenticated with an empty password. LDAP servers can be configured to fail Unauthenticated Bind requests with a resultCode of “unwillingToPerform” to prevent this occurring.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    6.6.2 – 6.6.0,
    6.5.x

    Versione di correzione:

    6.6.3

  • Index Service is leaking internal administrative credentials into the logging.

    Internal rest calls (/listCreateTokens, /listRebalanceTokens, /listMetadataTokens) are getting logged into the indexer.log with unredacted Base64 encoded authentication information for internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    6.6.1,
    6.6.0,
    6.5.1,
    6.5.0,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    Versione di correzione:

    6.6.2,
    6.5.2

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.