카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Update golang.org/x/text package to 0.3.4 or later

    The golang.org/x/text/encoding/unicode package which could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x

    수정 버전:

    7.0.4,
    6.6.6

  • Backup Service log leaks unredacted usernames and doc ids

    If the backup service fails to log an audit message, it leaks the audit log data into the backup_service.log which isn’t redacted.

    상품

    카우치베이스 서버

    영향

    Low (1.8)

    영향을 받는 버전:

    7.0.x

    수정 버전:

    7.1.0

  • Analytics Remote Links may temporarily downgrade to non-TLS connection to determine TLS port

    On failure to establish TLS connection for an Analytics Remote Link configured with encryption=full, the runtime would attempt to discover the (non-default) TLS port by attempting a non-TLS connection to the remote cluster, using SCRAM-SHA for authentication. While credentials are not shared when SCRAM-SHA, it may not be expected that the system would downgrade the prescribed encryption level which specified a TLS connection. This fallback mechanism has been removed, and in a failure to initially establish a TLS connection, the CONNECT LINK will simply fail until the correct TLS port is provided as part of the link configuration.

    상품

    카우치베이스 서버

    영향

    Low (2.0)

    영향을 받는 버전:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0

    수정 버전:

    7.0.4,
    6.6.6

  • Field names are not redacted in logged validation messages for Analytics Service

    When creating secondary indexes with the Couchbase Server Analytics Service, there are some validations on the indexed fields which are reported to the user and logged. The error message with code ASX0013 is used in multiple paths to report and log that there is a duplicate field name. The field names in these logged validation messages are not redacted. Also errors with the code ASX1079 has field names which are not redacted.

    상품

    카우치베이스 서버

    영향

    Low (1.8)

    영향을 받는 버전:

    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x

    수정 버전:

    7.0.4,
    6.6.6

  • Untrusted node addition can be manipulated in order to harvest a cluster secret

    Administrators adding an untrusted node to a cluster could inadvertently risk transmitting the cluster cookie which should remain secret. This can be addressed by deploying TLS encryption with Certificate Authority signed certificates. When using TLS, a trusted certificate is required to be present on the incoming node from Couchbase Server version 7.1.0. Recognition: Ofir Hamam, security researcher at EY Israel’s Advanced Security Center

    상품

    카우치베이스 서버

    영향

    High (7.6)

    영향을 받는 버전:

    7.0.3 – 7.0.0,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    수정 버전:

    7.1.0

  • Secrets not redacted in logs collected from Kubernetes environments

    Couchbase Operator 2.2.0 introduced an optimization that simplified log collection. When logs are collected, the support tool – “cbopinfo” – is used to collect Kubernetes resources necessary to gain insight into intended resource state, and current resource status. Prior to the affected versions, secret data was redacted, however this functionality was not retained in the new collection method. As a result, logs would have erroneously contained any passwords, tokens, and private keys within the scope of the log collection. By default, this scope will be limited to the Kubernetes namespace in which the Couchbase Server cluster under inspection resides. The exception to this is if the –system flag was specified, in which case all secrets on the platform will have been exposed. Logs are used to identify and remediate customer issues, and therefore only customers that have supplied logs, with the specified tool versions, are affected. Couchbase will ensure that all affected logs which have been provided are redacted.

    상품

    Couchbase Cloud Native Operator

    영향

    High (7.2)

    영향을 받는 버전:

    2.2.0,
    2.2.1,
    2.2.2

    수정 버전:

    2.2.3

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.