Avvisi di Couchbase

In questa pagina sono elencati gli avvisi e i consigli critici per Couchbase.

Rimanete informati sugli ultimi avvisi e avvisi critici per Couchbase Server iscrivendovi alle nostre notifiche di aggiornamento. Per iscriversi, registrarsi sul nostro sito di supporto e seguire questo articolo: Annunci – Supporto Couchbase

Avvisi di Sicurezza Aziendale

  • Update of Apache Parquet to 1.12.3

    An attacker can use Parquet files, as optionally used by the Couchbase Analytics Service, to cause a Denial of Service (DoS) if malicious files contain improper values in the file page header (e.g. negative values where positive value is expected). This is resolved by updating the Apache Parquet library to a later version.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.1.1,
    7.1.0

    Versione di correzione:

    7.1.2

  • Update of js-beautify to 1.14.3, a client-side javascript library used in the Couchbase Server UI

    js-beautify has a dependency with a known vulnerability, Minimist. Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Prototype pollution attacks allow bypassing input validation and triggering unexpected javascript execution.

    Prodotti:

    Couchbase Server

    Impatto

    Critico (9.8)

    Versioni interessate:

    7.1.0,
    7.0.x

    Versione di correzione:

    7.1.1

  • Updating ramda, a client-side javascript library to version 0.28 as used in the Couchbase Server UI

    Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property “{}proto{}”) as an argument to the function, known as prototype pollution. Prototype pollution type attacks allow bypassing input validation and triggering unexpected javascript execution.

    Prodotti:

    Couchbase Server

    Impatto

    Critical (9.1)

    Versioni interessate:

    7.1.0,
    7.0.x

    Versione di correzione:

    7.1.1

  • Encrypted Private Key passphrase may be leaked in the logs

    In Couchbase Server 7.1.0 and later it’s possible to provide a passphrase to Couchbase Server to unlock an encrypted TLS private key. This passphrase was found to be leaked in the log files as a Base64 encoded string when one of the Couchbase services, other than the Data Service, was starting up. This affects the Index Service, Query Service, Analytics Service, Backup Service and Eventing Service if the optional encrypted TLS keys feature is used. Note, an attacker needs to have access to the logs as well as the private key to be able to perform attacks such as performing a man in the middle attack or decrypting network communication. Using operating system protections to restrict access to these files can be an effective mitigation strategy.

    Prodotti:

    Couchbase Server

    Impatto

    Medium (4.4)

    Versioni interessate:

    7.1.0

    Versione di correzione:

    7.1.1

  • Update of jackson-databind library to version 2.13.2.2

    jackson-databind, before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. This library is used by the Couchbase Server Analytics Service.

    Prodotti:

    Couchbase Server

    Impatto

    Medio (6,5)

    Versioni interessate:

    7.1.0,
    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x

    Versione di correzione:

    7.1.1,
    7.0.4,
    6.6.6

  • Update of GoLang to a minimum of 1.17.9 or 1.18.1

    Updated Go Programming Language and associated libraries used in multiple Couchbase Server services to versions 1.17.9+ or 1.18.1+ to resolve numerous CVEs.

    Prodotti:

    Couchbase Server

    Impatto

    High (7.5)

    Versioni interessate:

    7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x

    Versione di correzione:

    7.1.1,
    7.0.5,
    6.6.6

Iniziare a costruire

Scopri il nostro portale per sviluppatori per esplorare NoSQL, consultare risorse e iniziare con i tutorial.

Utilizzare Capella gratuitamente

Per iniziare a lavorare con Couchbase bastano pochi clic. Capella DBaaS è il modo più semplice e veloce per iniziare.

Contattaci

Volete saperne di più sulle offerte di Couchbase? Lasciatevi aiutare.