Esta página lista os alertas e avisos críticos do Couchbase.
Mantenha-se informado sobre os alertas e avisos críticos mais recentes do Couchbase Server assinando nossas notificações de atualização. Para se inscrever, registre-se em nosso site de suporte e siga este artigo: Anúncios – Suporte Couchbase
Alertas de Segurança Empresarial
-
Query Service stats endpoint was accessible without authentication
The Query stats endpoint did not implement correct authentication, making it possible to view the stats information
-
Private key leak in debug.log while adding pre-7.0 node to 7.2 cluster
The private key is leaked to debug.log when adding a pre-7.0 node to 7.2 cluster.
-
Unauthenticated users may cause memcached to run out of memory
A malicious user may easily crash a memcached server by connecting to the server and start sending large commands.
-
Windows traversal security issue
The Couchbase Server Windows UI allows an attacker to traverse the filesystem and display files that Couchbase has access to. This vulnerability doesn’t require any authentication. It’s exploitable with just appending folders/files to the Couchbase Server admin UI’s URL.
-
Update OpenJDK to 11.0.19
Update OpenJDK to versions 11.0.19 to resolve numerous CVEs.
-
Update V8 to 11.4.185.1
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.