Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • Update of V8 Javascript Engine to 10.7.x

    The v8 Javascript engine as used in the Couchbase Server Eventing Service, View Engine, XDCR and N1QL UDFs has been updated as there’s a type confusion in versions prior to 99.0.4844.84 which allowed a remote attacker to potentially exploit heap corruption via a crafted request.

    Prodotti:

    Couchbase Server

    Impatto

    High (8.8)

    Versioni interessate:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.1.2,
    7.0.5

  • A crafted HTTP request to REST API can cause a backup service OOM

    An extremely large (or unbounded) HTTP request body may cause the backup service to cause an OOM (out-of-memory) error.

    Prodotti:

    Couchbase Server

    Impatto

    Medio (4.9)

    Versioni interessate:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0

    Versione di correzione:

    7.1.2,
    7.0.5

  • Update of Jackson Databind to 2.13.4.2+ as used in the Analytics Service to resolve vulnerabilities

    A resource exhaustion of the Couchbase Analytics Service can occur because of a lack of a check to prevent use of deeply nested arrays.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.1.2 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x

    Versione di correzione:

    7.1.3,
    7.0.5,
    6.6.6

  • Couchbase Cluster Manager lacks access controls during a cluster node restart

    During the start of a couchbase server node there is a short time period where the security cookie is set to “nocookie” which lacks access controls over the Erlang distribution protocol. If an attacker connects to this protocol during this period, they can execute arbitrary code remotely on any cluster node at any point of time until their connection is dropped. The executed code will be running with the same privileges as the Couchbase Server.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    Versione di correzione:

    7.1.2,
    7.0.5,
    6.6.6

  • Credentials can be leaked to the logs if there is a crash during a node join.

    During a node join failure, unredacted credentials of the user making the REST request can be leaked into the log files.

    Prodotti:

    Couchbase Server

    Impatto

    Medium (6.3)

    Versioni interessate:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x,
    3.x,
    2.x

    Versione di correzione:

    7.1.2,
    7.0.5,
    6.6.6

  • Upgrade of Erlang to version 24.3.4.4

    When using the tls/ssl feature in couchbase server, it is possible to bypass client authentication in certain situations. Specifically, any application using the ssl/tls/dtls server, and the client certification option “{verify, verify_peer}” are affected by this vulnerability. Corrections have been released on the supported tracks with patches 23.3.4.15, 24.3.4.2, and 25.0.2 of the erlang/OTP runtime. Only clusters using certificate-based authentication are affected.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    7.1.1,
    7.1.0

    Versione di correzione:

    7.1.2

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.