Couchbaseアラート

このページでは、Couchbaseの重要なアラートとアドバイザリを一覧表示します。

更新通知を購読することで、Couchbase Serverの最新の重要なアラートとアドバイザリに関する情報を入手できます。登録するには、当社のサポートサイトに登録し、この記事に従ってください: お知らせ – Couchbase サポート

エンタープライズセキュリティアラート

  • Update of V8 Javascript Engine to 10.7.x

    The v8 Javascript engine as used in the Couchbase Server Eventing Service, View Engine, XDCR and N1QL UDFs has been updated as there’s a type confusion in versions prior to 99.0.4844.84 which allowed a remote attacker to potentially exploit heap corruption via a crafted request.

    製品

    Couchbase Server

    影響

    高 (8.8)

    影響バージョン:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.1.2,
    7.0.5

  • A crafted HTTP request to REST API can cause a backup service OOM

    An extremely large (or unbounded) HTTP request body may cause the backup service to cause an OOM (out-of-memory) error.

    製品

    Couchbase Server

    影響

    中 (4.9)

    影響バージョン:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0

    修正バージョン

    7.1.2,
    7.0.5

  • Update of Jackson Databind to 2.13.4.2+ as used in the Analytics Service to resolve vulnerabilities

    A resource exhaustion of the Couchbase Analytics Service can occur because of a lack of a check to prevent use of deeply nested arrays.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.1.2 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x

    修正バージョン

    7.1.3,
    7.0.5,
    6.6.6

  • Couchbase Cluster Manager lacks access controls during a cluster node restart

    During the start of a couchbase server node there is a short time period where the security cookie is set to “nocookie” which lacks access controls over the Erlang distribution protocol. If an attacker connects to this protocol during this period, they can execute arbitrary code remotely on any cluster node at any point of time until their connection is dropped. The executed code will be running with the same privileges as the Couchbase Server.

    製品

    Couchbase Server

    影響

    クリティカル(9.8)

    影響バージョン:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    修正バージョン

    7.1.2,
    7.0.5,
    6.6.6

  • Credentials can be leaked to the logs if there is a crash during a node join.

    During a node join failure, unredacted credentials of the user making the REST request can be leaked into the log files.

    製品

    Couchbase Server

    影響

    Medium (6.3)

    影響バージョン:

    7.1.1 – 7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x,
    3.x,
    2.x

    修正バージョン

    7.1.2,
    7.0.5,
    6.6.6

  • Upgrade of Erlang to version 24.3.4.4

    When using the tls/ssl feature in couchbase server, it is possible to bypass client authentication in certain situations. Specifically, any application using the ssl/tls/dtls server, and the client certification option “{verify, verify_peer}” are affected by this vulnerability. Corrections have been released on the supported tracks with patches 23.3.4.15, 24.3.4.2, and 25.0.2 of the erlang/OTP runtime. Only clusters using certificate-based authentication are affected.

    製品

    Couchbase Server

    影響

    クリティカル(9.8)

    影響バージョン:

    7.1.1,
    7.1.0

    修正バージョン

    7.1.2

建設開始

当社の開発者ポータルをチェックして、NoSQLを探求し、リソースを閲覧し、チュートリアルから始めましょう。

カペラを無料で利用

わずか数クリックでCouchbaseをハンズオン。Capella DBaaSは、最も簡単かつ迅速に始めることができます。

連絡先

Couchbaseのサービスについてもっと知りたいですか?私たちにお任せください。