Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • Credentials are negotiated with KV using SCRAM-SHA when remote link encryption is configured for HALF

    SDK will negotiate with SCRAM-SHA by default which allows for a MITM to negotiate for PLAIN credentials

    Prodotti:

    Couchbase Server

    Impatto

    Medium (5.9)

    Versioni interessate:

    7.6.0,
    7.2.4,
    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x

    Versione di correzione:

    7.6.1,
    7.2.5

  • Upgrade to OpenSSL 3.1.4

    Applications that use the functions DH_generate_key() to generate an X9.42 DH key and applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.

    Prodotti:

    Couchbase Server

    Impatto

    Medium (5.3)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.2.4

  • Upgrade cURL to 8.4.0

    The flaw in curl makes it overflow a heap based buffer in the SOCKS5 proxy handshake.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Versione di correzione:

    7.2.4

  • TLS Private key leaked in XDCR log file

    The private key used for Cross Datacenter Replication (XDCR) was leaked in the goxdcr.log

    Prodotti:

    Couchbase Server

    Impatto

    Low (2.1)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.5.x

    Versione di correzione:

    7.2.4

  • The internal Full Admin user for cluster management credentials leaked to log file

    A logging event caused the internal @ns_server admin credentials to be leaked in encoded form in diag.log.

    Prodotti:

    Couchbase Server

    Impatto

    Low (2.1)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.6,
    7.1.5

    Versione di correzione:

    Server 7.2.4

  • Eventing SQL++ cURL calls to /diag/eval were not sufficiently restricted

    Calling cURL via SQL++ (N1QL) via the Eventing Service to the local host’s /diag/eval endpoint wasn’t fully prevented.

    Prodotti:

    Couchbase Server

    Impatto

    High (8.6)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.5.x

    Versione di correzione:

    Server 7.2.4

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.