CRITICAL🇵🇱 Wersja polska

CVE-2020-9039

CVSS 9.8v3.1pub. 2020-02-22upd. 2024-11-21

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Couchbase Server

    APP
    Couchbase
    4.0.04.1.04.1.14.5.04.5.15.0.05.1.15.5.05.5.14.6.0 – 4.6.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-49931CRITICAL9.8PL ✓same product

Niewystarczające ograniczenia wywołań cURL w Couchbase Server (SQL++)

CVE-2023-49930CRITICAL9.8PL ✓same product

Niewystarczające ograniczenia wywołań cURL w /diag/eval w Couchbase Server

CVE-2022-32559CRITICAL9.1PL ✓same product

Wyciek metryk systemowych przez losowe żądania HTTP w Couchbase Server

CVE-2021-35943CRITICAL9.8PL ✓same product

Couchbase Server: Auth Bypass przez puste hasło użytkownika zewnętrznego

CVE-2020-24719CRITICAL9.8PL ✓same product

RCE w Couchbase Server przez ujawniony Erlang Cookie w logach