Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • Query Service stats endpoint was accessible without authentication

    The Query stats endpoint did not implement correct authentication, making it possible to view the stats information

    Prodotti:

    Couchbase Server

    Impatto

    Medium (5.3)

    Versioni interessate:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x

    Versione di correzione:

    7.2.4

  • Private key leak in debug.log while adding pre-7.0 node to 7.2 cluster

    The private key is leaked to debug.log when adding a pre-7.0 node to 7.2 cluster.

    Prodotti:

    Couchbase Server

    Impatto

    Medium (4.4)

    Versioni interessate:

    7.2.0

    Versione di correzione:

    7.2.1

  • Unauthenticated users may cause memcached to run out of memory

    A malicious user may easily crash a memcached server by connecting to the server and start sending large commands.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    Versione di correzione:

    7.2.1,
    7.1.5

  • Windows traversal security issue

    The Couchbase Server Windows UI allows an attacker to traverse the filesystem and display files that Couchbase has access to. This vulnerability doesn’t require any authentication. It’s exploitable with just appending folders/files to the Couchbase Server admin UI’s URL.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.2.1,
    7.1.5

  • Update OpenJDK to 11.0.19

    Update OpenJDK to versions 11.0.19 to resolve numerous CVEs.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.4)

    Versioni interessate:

    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    Versione di correzione:

    7.1.5

  • Update V8 to 11.4.185.1

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Prodotti:

    Couchbase Server

    Impatto

    High (8.0)

    Versioni interessate:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.2.1,
    7.1.5

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.