Couchbaseアラート

このページでは、Couchbaseの重要なアラートとアドバイザリを一覧表示します。

更新通知を購読することで、Couchbase Serverの最新の重要なアラートとアドバイザリに関する情報を入手できます。登録するには、当社のサポートサイトに登録し、この記事に従ってください: お知らせ – Couchbase サポート

エンタープライズセキュリティアラート

  • Update golang.org/x/text package to 0.3.4 or later

    The golang.org/x/text/encoding/unicode package which could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x

    修正バージョン

    7.0.4,
    6.6.6

  • Backup Service log leaks unredacted usernames and doc ids

    If the backup service fails to log an audit message, it leaks the audit log data into the backup_service.log which isn’t redacted.

    製品

    Couchbase Server

    影響

    Low (1.8)

    影響バージョン:

    7.0.x

    修正バージョン

    7.1.0

  • Analytics Remote Links may temporarily downgrade to non-TLS connection to determine TLS port

    On failure to establish TLS connection for an Analytics Remote Link configured with encryption=full, the runtime would attempt to discover the (non-default) TLS port by attempting a non-TLS connection to the remote cluster, using SCRAM-SHA for authentication. While credentials are not shared when SCRAM-SHA, it may not be expected that the system would downgrade the prescribed encryption level which specified a TLS connection. This fallback mechanism has been removed, and in a failure to initially establish a TLS connection, the CONNECT LINK will simply fail until the correct TLS port is provided as part of the link configuration.

    製品

    Couchbase Server

    影響

    Low (2.0)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0

    修正バージョン

    7.0.4,
    6.6.6

  • Field names are not redacted in logged validation messages for Analytics Service

    When creating secondary indexes with the Couchbase Server Analytics Service, there are some validations on the indexed fields which are reported to the user and logged. The error message with code ASX0013 is used in multiple paths to report and log that there is a duplicate field name. The field names in these logged validation messages are not redacted. Also errors with the code ASX1079 has field names which are not redacted.

    製品

    Couchbase Server

    影響

    Low (1.8)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    修正バージョン

    7.0.4,
    6.6.6

  • Untrusted node addition can be manipulated in order to harvest a cluster secret

    Administrators adding an untrusted node to a cluster could inadvertently risk transmitting the cluster cookie which should remain secret. This can be addressed by deploying TLS encryption with Certificate Authority signed certificates. When using TLS, a trusted certificate is required to be present on the incoming node from Couchbase Server version 7.1.0. 認識 Ofir Hamam, security researcher at EY Israel’s Advanced Security Center

    製品

    Couchbase Server

    影響

    高 (7.6)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.1.0

  • Secrets not redacted in logs collected from Kubernetes environments

    Couchbase Operator 2.2.0 introduced an optimization that simplified log collection. When logs are collected, the support tool – “cbopinfo” – is used to collect Kubernetes resources necessary to gain insight into intended resource state, and current resource status. Prior to the affected versions, secret data was redacted, however this functionality was not retained in the new collection method. As a result, logs would have erroneously contained any passwords, tokens, and private keys within the scope of the log collection. By default, this scope will be limited to the Kubernetes namespace in which the Couchbase Server cluster under inspection resides. The exception to this is if the –system flag was specified, in which case all secrets on the platform will have been exposed. Logs are used to identify and remediate customer issues, and therefore only customers that have supplied logs, with the specified tool versions, are affected. Couchbase will ensure that all affected logs which have been provided are redacted.

    製品

    Couchbase Cloud Native Operator

    影響

    High (7.2)

    影響バージョン:

    2.2.0,
    2.2.1,
    2.2.2

    修正バージョン

    2.2.3

建設開始

当社の開発者ポータルをチェックして、NoSQLを探求し、リソースを閲覧し、チュートリアルから始めましょう。

カペラを無料で利用

わずか数クリックでCouchbaseをハンズオン。Capella DBaaSは、最も簡単かつ迅速に始めることができます。

連絡先

Couchbaseのサービスについてもっと知りたいですか?私たちにお任せください。