Esta página lista os alertas e avisos críticos do Couchbase.
Mantenha-se informado sobre os alertas e avisos críticos mais recentes do Couchbase Server assinando nossas notificações de atualização. Para se inscrever, registre-se em nosso site de suporte e siga este artigo: Anúncios – Suporte Couchbase
Alertas de Segurança Empresarial
-
Update of GoLang to 1.19.9
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
-
Upgrade to OpenSSL 1.1.1u
A vulnerability in OpenSSL related to the verification of X.509 certificate chains that include policy constraints., which would allow attackers to be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.
-
Upgrade Golang to 1.20.10
The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.
-
Upgrade gRPC to v1.58.3
The HTTP/2 protocol allows a denial of service because request cancellation can reset many streams quickly.
-
Update Netty to 4.1.86.Final or higher
In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.
-
Full Text Search (FTS) nsstats endpoint is accessible without authentication
The FTS stats endpoint at /api/nsstats does not implement correct authentication, so it is possible to view the names of Couchbase Server buckets, the names of FTS indexes and configuration of FTS indexes without authentication. The contents of the buckets and indexes are not exposed.