카우치베이스 알림

이 페이지에는 Couchbase에 대한 중요 알림 및 권고가 나열되어 있습니다.

업데이트 알림을 구독하여 Couchbase Server에 대한 최신 중요 경고 및 권고에 대한 정보를 받아보세요. 가입하려면 지원 사이트에서 등록하고 이 문서를 따르세요: 공지사항 – Couchbase 지원

기업 보안 경고

  • Update of Apache Parquet to 1.12.3

    An attacker can use Parquet files, as optionally used by the Couchbase Analytics Service, to cause a Denial of Service (DoS) if malicious files contain improper values in the file page header (e.g. negative values where positive value is expected). This is resolved by updating the Apache Parquet library to a later version.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.1.1,
    7.1.0

    수정 버전:

    7.1.2

  • Update of js-beautify to 1.14.3, a client-side javascript library used in the Couchbase Server UI

    js-beautify has a dependency with a known vulnerability, Minimist. Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Prototype pollution attacks allow bypassing input validation and triggering unexpected javascript execution.

    상품

    카우치베이스 서버

    영향

    치명타 (9.8)

    영향을 받는 버전:

    7.1.0,
    7.0.x

    수정 버전:

    7.1.1

  • Updating ramda, a client-side javascript library to version 0.28 as used in the Couchbase Server UI

    Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property “{}proto{}”) as an argument to the function, known as prototype pollution. Prototype pollution type attacks allow bypassing input validation and triggering unexpected javascript execution.

    상품

    카우치베이스 서버

    영향

    Critical (9.1)

    영향을 받는 버전:

    7.1.0,
    7.0.x

    수정 버전:

    7.1.1

  • Encrypted Private Key passphrase may be leaked in the logs

    In Couchbase Server 7.1.0 and later it’s possible to provide a passphrase to Couchbase Server to unlock an encrypted TLS private key. This passphrase was found to be leaked in the log files as a Base64 encoded string when one of the Couchbase services, other than the Data Service, was starting up. This affects the Index Service, Query Service, Analytics Service, Backup Service and Eventing Service if the optional encrypted TLS keys feature is used. Note, an attacker needs to have access to the logs as well as the private key to be able to perform attacks such as performing a man in the middle attack or decrypting network communication. Using operating system protections to restrict access to these files can be an effective mitigation strategy.

    상품

    카우치베이스 서버

    영향

    Medium (4.4)

    영향을 받는 버전:

    7.1.0

    수정 버전:

    7.1.1

  • Update of jackson-databind library to version 2.13.2.2

    jackson-databind, before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. This library is used by the Couchbase Server Analytics Service.

    상품

    카우치베이스 서버

    영향

    중간 (6.5)

    영향을 받는 버전:

    7.1.0,
    7.0.3 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x

    수정 버전:

    7.1.1,
    7.0.4,
    6.6.6

  • Update of GoLang to a minimum of 1.17.9 or 1.18.1

    Updated Go Programming Language and associated libraries used in multiple Couchbase Server services to versions 1.17.9+ or 1.18.1+ to resolve numerous CVEs.

    상품

    카우치베이스 서버

    영향

    High (7.5)

    영향을 받는 버전:

    7.1.0,
    7.0.4 – 7.0.0,
    6.6.5 – 6.6.0,
    6.5.x,
    6.0.x,
    5.x,
    4.x

    수정 버전:

    7.1.1,
    7.0.5,
    6.6.6

구축 시작

개발자 포털에서 NoSQL을 살펴보고, 리소스를 찾아보고, 튜토리얼을 시작하세요.

카펠라 무료 사용

클릭 몇 번으로 Couchbase를 직접 체험해 보세요. Capella DBaaS는 가장 쉽고 빠르게 시작할 수 있는 방법입니다.

연락하기

카우치베이스 제품에 대해 자세히 알고 싶으신가요? 저희가 도와드리겠습니다.