Couchbaseアラート

このページでは、Couchbaseの重要なアラートとアドバイザリを一覧表示します。

更新通知を購読することで、Couchbase Serverの最新の重要なアラートとアドバイザリに関する情報を入手できます。登録するには、当社のサポートサイトに登録し、この記事に従ってください: お知らせ – Couchbase サポート

エンタープライズセキュリティアラート

  • Query Service stats endpoint was accessible without authentication

    The Query stats endpoint did not implement correct authentication, making it possible to view the stats information

    製品

    Couchbase Server

    影響

    中(5.3)

    影響バージョン:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x

    修正バージョン

    7.2.4

  • Private key leak in debug.log while adding pre-7.0 node to 7.2 cluster

    The private key is leaked to debug.log when adding a pre-7.0 node to 7.2 cluster.

    製品

    Couchbase Server

    影響

    Medium (4.4)

    影響バージョン:

    7.2.0

    修正バージョン

    7.2.1

  • Unauthenticated users may cause memcached to run out of memory

    A malicious user may easily crash a memcached server by connecting to the server and start sending large commands.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    修正バージョン

    7.2.1,
    7.1.5

  • Windows traversal security issue

    The Couchbase Server Windows UI allows an attacker to traverse the filesystem and display files that Couchbase has access to. This vulnerability doesn’t require any authentication. It’s exploitable with just appending folders/files to the Couchbase Server admin UI’s URL.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.2.1,
    7.1.5

  • Update OpenJDK to 11.0.19

    Update OpenJDK to versions 11.0.19 to resolve numerous CVEs.

    製品

    Couchbase Server

    影響

    High (7.4)

    影響バージョン:

    7.1.4 – 7.1.0,
    7.0.x,
    6.6.x

    修正バージョン

    7.1.5

  • Update V8 to 11.4.185.1

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    製品

    Couchbase Server

    影響

    High (8.0)

    影響バージョン:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.2.1,
    7.1.5

建設開始

当社の開発者ポータルをチェックして、NoSQLを探求し、リソースを閲覧し、チュートリアルから始めましょう。

カペラを無料で利用

わずか数クリックでCouchbaseをハンズオン。Capella DBaaSは、最も簡単かつ迅速に始めることができます。

連絡先

Couchbaseのサービスについてもっと知りたいですか?私たちにお任せください。