Couchbaseアラート

このページでは、Couchbaseの重要なアラートとアドバイザリを一覧表示します。

更新通知を購読することで、Couchbase Serverの最新の重要なアラートとアドバイザリに関する情報を入手できます。登録するには、当社のサポートサイトに登録し、この記事に従ってください: お知らせ – Couchbase サポート

エンタープライズセキュリティアラート

  • Private key is leaked to the log files with certain crashes

    Certain rare crashes might cause the private key of the generated certificate to be leaked to the log files.

    製品

    Couchbase Server

    影響

    Medium (6.3)

    影響バージョン:

    7.1.0,
    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x,
    3.x

    修正バージョン

    7.1.1,
    7.0.4,
    6.6.6

  • Admin credentials not verified when using X.509 client cert authentication from Sync Gateway to Couchbase Server

    When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials provided to the Admin REST API are ignored, resulting in privilege escalation for unauthenticated users. The Public REST API is not impacted by this issue. Workaround: Replace X.509 certificate based authentication with Username and Password authentication inside the bootstrap configuration.

    製品

    Couchbase Sync Gateway

    影響

    クリティカル(9.8)

    影響バージョン:

    3.0.0,
    3.0.1

    修正バージョン

    3.0.2

  • Random http requests lead to leaked metrics

    Unauthenticated users can make a REST API call to the cluster manager. Each http request that has not been seen before by the cluster manager leads to a creation of a new metric. Each new metric takes some memory and some disk space, which can create a memory leak and disk space leak. If enough resources are used, it could cause a Couchbase Server node to fail.

    製品

    Couchbase Server

    影響

    高 (7.5)

    影響バージョン:

    7.0.3 – 7.0.0

    修正バージョン

    7.0.4

  • Index Service does not enforce authentication for TCP/TLS servers

    The Index Service runs several network processes, Queryport, Dataport and Adminport. These are used to communicate with other Couchbase services. These processes take part in node to node communication, but do not communicate directly with SDK applications. In the affected versions of Couchbase Server, these network processes do not enforce authentication, so will process requests sent by unauthenticated users. Queryport server can respond to an unauthenticated user with index scan results. Dataport server can allow unauthenticated user to modify indexed data. Adminport server can allow unauthenticated user to perform DDL operations (like Create and Drop index). Possible workaround: As these ports are used only for internal communication by Couchbase Server, any connections/communication with non-Couchbase Server nodes and processes can be disabled at the network layer.

    製品

    Couchbase Server

    影響

    High (8.2)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.x,
    5.x,
    4.x

    修正バージョン

    7.0.4

  • Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network

    Diagnostic endpoints such as diag/eval are restricted and can only be executed from the loopback network. However, the checks put in place to address CVE-2018-15728 do not correctly check if a “X-Forwarded-For” header contains a loopback address. This header can be manipulated to workaround the loopback restriction. The vulnerability is limited to requests originating from private network and shared address spaces, per RFC6890. To be able to successfully issue requests to these endpoints a user requires full administrative privileges, regardless of “X-Forwarded-For” header used. A workaround for this issue is to firewall requests to the Couchbase Server nodes that contain “X-Forwarded-For” headers in environments where they are not required. 認識 Mucahit Karadag / PRODAFT

    製品

    Couchbase Server

    影響

    高 (8.8)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.6.4 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x

    修正バージョン

    6.6.5,
    7.0.4

  • Private key may be logged during a crash of the Cluster Manager component of Couchbase Server

    While performing cluster node additions, a crash of the Cluster Manager (ns_server) may lead to the private key getting leaked into the log files. Someone who has access to the log files may be able to decrypt secure network connections to the cluster. If TLS is used the credentials of users and applications that login into the cluster may be acquired.

    製品

    Couchbase Server

    影響

    Medium (6.3)

    影響バージョン:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0

    修正バージョン

    7.0.4,
    6.6.6

建設開始

当社の開発者ポータルをチェックして、NoSQLを探求し、リソースを閲覧し、チュートリアルから始めましょう。

カペラを無料で利用

わずか数クリックでCouchbaseをハンズオン。Capella DBaaSは、最も簡単かつ迅速に始めることができます。

連絡先

Couchbaseのサービスについてもっと知りたいですか?私たちにお任せください。