카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Update of GoLang to 1.19.9

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    수정 버전:

    7.2.1,
    7.1.5

  • Upgrade to OpenSSL 1.1.1u

    A vulnerability in OpenSSL related to the verification of X.509 certificate chains that include policy constraints., which would allow attackers to be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.2.0,
    7.1.4 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x,
    3.x,
    2.x

    수정 버전:

    7.2.1,
    7.1.5

  • Upgrade Golang to 1.20.10

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    수정 버전:

    7.2.3,
    7.1.6

  • Upgrade gRPC to v1.58.3

    The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.2.2 – 7.2.0,
    7.1.5 – 7.1.0,
    7.0.x,
    6.x,
    5.x,
    4.x

    수정 버전:

    7.2.3,
    7.1.6

  • Update Netty to 4.1.86.Final or higher

    In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.

    상품

    카우치베이스 서버

    영향

    Low (2.2)

    영향을 받는 버전:

    6.6.6,
    7.0.5,
    7.1.3

    수정 버전:

    7.2.0,
    7.1.4

  • Full Text Search (FTS) nsstats endpoint is accessible without authentication

    The FTS stats endpoint at /api/nsstats does not implement correct authentication, so it is possible to view the names of Couchbase Server buckets, the names of FTS indexes and configuration of FTS indexes without authentication. The contents of the buckets and indexes are not exposed.

    상품

    카우치베이스 서버

    영향

    Medium (5.3)

    영향을 받는 버전:

    7.1.3 – 7.1.0,
    7.0.x,
    6.6.x

    수정 버전:

    7.1.4

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.