In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
References
Link | Resource |
---|---|
https://www.couchbase.com/resources/security#SecurityAlerts | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-09-10 11:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-11466
Mitre link : CVE-2019-11466
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
couchbase
- couchbase_server