Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • SQL++ N1QL cURL host restrictions implementation issue

    The SQL++ (N1QL) cURL allowlist protection in the Query Service, wasn’t sufficient in preventing accessing restricted hosts.

    Prodotti:

    Couchbase Server

    Impatto

    Medium (5.3)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x

    Versione di correzione:

    7.2.4

  • SQL++ cURL calls to /diag/eval were not sufficiently restricted

    Calling cURL via SQL++ (N1QL) using the Query Service to the localhost’s /diag/eval endpoint wasn’t fully prevented.

    Prodotti:

    Couchbase Server

    Impatto

    High (8.6)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x

    Versione di correzione:

    7.2.4

  • otpCookie was shown to a user with a Full Admin role on the Cluster Manager’s API endpoints serverGroups and engageCluster2

    The cluster’s otpCookie was leaked to users with Full Admin role on API endpoint serverGroups and both Cluster Admin and Full Admin on API endpoint engageCluster2. This could be used to elevate privileges

    Prodotti:

    Couchbase Server

    Impatto

    High (8.6)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.2.4

  • Unauthenticated RMI Service Ports Exposed in Analytics Service

    Network ports 9119 and 9121 were unauthenticated RMI service ports hosted by the Analytics Service which could result in privilege escalation.

    Prodotti:

    Couchbase Server

    Impatto

    Critical (9.1)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x

    Versione di correzione:

    Server 7.2.4

  • Data readers could DOS the reader threads

    A user with Data Reader role could lock a Data Service reader thread for a significant time by requesting a high number of keys and potentially lock up all reader threads by issuing the same command on multiple connections

    Prodotti:

    Couchbase Server

    Impatto

    Medium (4.3)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Versione di correzione:

    Server 7.2.4

  • User with Data Reader role could OOM kill the Data Service

    A user with the Data Reader privilege could kill the Data Service by sending GetKeys requesting a high number of documents, triggering a Out-of-Memory (OOM) error.

    Prodotti:

    Couchbase Server

    Impatto

    Medio (6,5)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    Versione di correzione:

    Server 7.2.4

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.