Couchbaseアラート

このページでは、Couchbaseの重要なアラートとアドバイザリを一覧表示します。

更新通知を購読することで、Couchbase Serverの最新の重要なアラートとアドバイザリに関する情報を入手できます。登録するには、当社のサポートサイトに登録し、この記事に従ってください: お知らせ – Couchbase サポート

エンタープライズセキュリティアラート

  • Update of GoLang to 1.19.9

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    修正バージョン

    7.2.1,
    7.1.5

  • Upgrade to OpenSSL 1.1.1u

    A vulnerability in OpenSSL related to the verification of X.509 certificate chains that include policy constraints., which would allow attackers to be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.2.1,
    7.1.5

  • Upgrade Golang to 1.20.10

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    修正バージョン

    7.2.3,
    7.1.6

  • Upgrade gRPC to v1.58.3

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    修正バージョン

    7.2.3,
    7.1.6

  • Update Netty to 4.1.86.Final or higher

    In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.

    製品

    Couchbase Server

    影響

    Low (2.2)

    影響バージョン:

    6.6.6,
    7.0.5,
    7.1.3

    修正バージョン

    7.2.0,
    7.1.4

  • Full Text Search (FTS) nsstats endpoint is accessible without authentication

    The FTS stats endpoint at /api/nsstats does not implement correct authentication, so it is possible to view the names of Couchbase Server buckets, the names of FTS indexes and configuration of FTS indexes without authentication. The contents of the buckets and indexes are not exposed.

    製品

    Couchbase Server

    影響

    中(5.3)

    影響バージョン:

    7.1.3 – 7.1.0,
    7.0.x,
    6.6.x

    修正バージョン

    7.1.4

建設開始

当社の開発者ポータルをチェックして、NoSQLを探求し、リソースを閲覧し、チュートリアルから始めましょう。

カペラを無料で利用

わずか数クリックでCouchbaseをハンズオン。Capella DBaaSは、最も簡単かつ迅速に始めることができます。

連絡先

Couchbaseのサービスについてもっと知りたいですか?私たちにお任せください。