카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Up until core-io 1.7.11 (and as a result Java SDK 2.7.11), hostname verification on TLS/SSL connections is not enabled and can be a security risk in certain environments.

    Java 6 (JDK 1.6 – the older SDK baseline version) did not support hostname verification out of the box. Once the SDK moved to Java 7 (Java 1.7) as the baseline, adding support was possible. This happened in jvm-core 1.7.11 (which translates to java-client 2.7.11). It is not possible in earlier versions to manually add it as a workaround, because the facilities to customize it accordingly are not exposed. Note that in order to not break applications that rely on the old behavior, hostname verification is still disabled by default, but can be enabled in the SDK configuration (CouchbaseEnvironment class).

    상품

    Couchbase Java SDK,
    Couchbase Spark Connector,
    Couchbase Kafka Connector,
    (Connectors depending on Java SDK or Core-IO)

    영향

    High (7.5)

    영향을 받는 버전:

    1.7.10,
    1.6.0,
    1.5.0,
    1.4.0,
    1.3.0,
    1.2.0,
    1.1.0,
    1.0.0

    수정 버전:

    2.7.11

  • Port 8092 misses X-XSS protection header.

    Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however, some information security professionals additionally look for X-Permitted-Cross-Domain-Policies and X-XSS-Protection, which are more generally applicable to HTML endpoints, to be included too. These headers are now included in responses from the Couchbase Server Views REST API (port 8092).

    상품

    카우치베이스 서버

    영향

    Medium (5.4)

    영향을 받는 버전:

    5.5.0,
    5.1.2

    수정 버전:

    6.0.2

  • Prevent N1QL injection in Sync Gateway via _all_docs startkey, endkey.

    An attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters “startkey” and “endkey” on the “_all_docs” endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication, and external access to this REST endpoint has been blocked to mitigate this issue. Recognition: Denis Werner/HiSolutions AG

    상품

    카우치베이스 동기화 게이트웨이

    영향

    High (7.6)

    영향을 받는 버전:

    2.1.2

    수정 버전:

    2.5.0,
    2.1.3

  • Memcached “connections” stat block command emits non-redacted username.

    The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.

    상품

    카우치베이스 서버

    영향

    중간 (6.5)

    영향을 받는 버전:

    6.0.0,
    5.5.3,
    5.5.2,
    5.5.1,
    5.5.0

    수정 버전:

    6.0.1,
    5.5.4

  • Eventing debug endpoint must enforce authentication.

    The eventing service exposes a system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied and now requires valid credentials to access.

    상품

    카우치베이스 서버

    영향

    High (7.1)

    영향을 받는 버전:

    6.0.0,
    5.5.0

    수정 버전:

    6.0.1

  • The /diag/eval endpoint is not locked down to localhost.

    Couchbase Server exposed the ‘/diag/eval’ endpoint, which, by default, is available on TCP/8091 and/or TCP/18091. Authenticated users that have ‘Full Admin‘ role assigned could send arbitrary Erlang code to the ‘diag/eval’ endpoint of the API and the code would subsequently be executed in the underlying operating system with privileges of the user which was used to start Couchbase. Recognition: Apple Security Team

    상품

    카우치베이스 서버

    영향

    High (8.8)

    영향을 받는 버전:

    5.5.1,
    5.5.0,
    5.1.1,
    5.0.1,
    5.0.0,
    4.6.5,
    4.5.1,
    4.1.2,
    4.0.0

    수정 버전:

    6.0.0,
    5.5.2

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.