카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Authentication information is leaked when invalid REST requests are received.

    When the Couchbase Server REST endpoint receives an unknown request, the request is logged as an error in the debug.log and info.log. The log includes unredacted Base64-encoded authentication information. The error message also is shown in the logs tab of the UI.

    상품

    카우치베이스 서버

    영향

    High (8.8)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    수정 버전:

    6.6.2

  • Update of the urllib3 library used by the Couchbase CLI to version 1.26.3

    The Python urllib3 library which is used by the requests Python library that in turn is used by the Couchbase CLI has a security issue in urllib3 versions before 1.24.2. The library mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    수정 버전:

    6.6.2

  • Update Apache HttpClient library used by Analytics Service to version 4.5.13

    The Apache HttpClient, as used by the Couchbase Server Analytics Service, in versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

    상품

    카우치베이스 서버

    영향

    Medium (5.3)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x

    수정 버전:

    6.6.2

  • Update of the buger/jsonparser library used by the Search Service to version 1.1.1

    A security issue in the buger/jsonparser (JSON parser for Go) library allows an attacker to cause a denial of service (DOS) in the Couchbase Server Search Service.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.2,
    6.5.1,
    6.5.0

    수정 버전:

    6.6.2

  • An unredacted session cookie was included in audit logs and debug.log for audited actions where a session ID was included

    Couchbase Server was logging the temporary session cookie for a user when audited events containing a session ID were logged to the audit log and debug.log. An attacker with access to logging data could use this to impersonate an authenticated user.

    상품

    카우치베이스 서버

    영향

    치명타 (9.8)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.x,
    6.0.x,
    5.5.x,
    5.1.x,
    5.0.x

    수정 버전:

    6.6.2

  • View Engine auditing condition leaks authentication information into the logs

    A rare condition that is triggered when Auditing is enabled for the View Engine and Node to Node encryption is enabled. If Couchbase Server is unable to check the remote hostname and port of an incoming internal command (view-merge request) over TLS, an error is logged which contains unredacted Base64 encoded authentication information for an internal user with administrator privileges, @ns_server. A temporary workaround is to disable View Engine auditing or Node to Node Encryption until an upgrade can be performed.

    상품

    카우치베이스 서버

    영향

    High (7.1)

    영향을 받는 버전:

    6.6.1,
    6.6.0,
    6.5.2,
    6.5.1,
    6.5.0

    수정 버전:

    6.6.2

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.