카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Credentials are negotiated with KV using SCRAM-SHA when remote link encryption is configured for HALF

    SDK will negotiate with SCRAM-SHA by default which allows for a MITM to negotiate for PLAIN credentials

    상품

    카우치베이스 서버

    영향

    Medium (5.9)

    영향을 받는 버전:

    7.6.0,
    7.2.4,
    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x

    수정 버전:

    7.6.1,
    7.2.5

  • Upgrade to OpenSSL 3.1.4

    Applications that use the functions DH_generate_key() to generate an X9.42 DH key and applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.

    상품

    카우치베이스 서버

    영향

    Medium (5.3)

    영향을 받는 버전:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    수정 버전:

    7.2.4

  • Upgrade cURL to 8.4.0

    The flaw in curl makes it overflow a heap based buffer in the SOCKS5 proxy handshake.

    상품

    카우치베이스 서버

    영향

    치명타 (9.8)

    영향을 받는 버전:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.6.x,
    6.5.x

    수정 버전:

    7.2.4

  • TLS Private key leaked in XDCR log file

    The private key used for Cross Datacenter Replication (XDCR) was leaked in the goxdcr.log

    상품

    카우치베이스 서버

    영향

    Low (2.1)

    영향을 받는 버전:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.x,
    5.x,
    4.5.x

    수정 버전:

    7.2.4

  • The internal Full Admin user for cluster management credentials leaked to log file

    A logging event caused the internal @ns_server admin credentials to be leaked in encoded form in diag.log.

    상품

    카우치베이스 서버

    영향

    Low (2.1)

    영향을 받는 버전:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.6,
    7.1.5

    수정 버전:

    Server 7.2.4

  • Eventing SQL++ cURL calls to /diag/eval were not sufficiently restricted

    Calling cURL via SQL++ (N1QL) via the Eventing Service to the local host’s /diag/eval endpoint wasn’t fully prevented.

    상품

    카우치베이스 서버

    영향

    High (8.6)

    영향을 받는 버전:

    7.2.3,
    7.2.2,
    7.2.1,
    7.2.0,
    7.1.x,
    7.0.x,
    6.5.x

    수정 버전:

    Server 7.2.4

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.