Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCouchbase Server
APPCouchbase4.0.04.1.04.1.14.5.04.5.15.0.05.1.15.5.05.5.14.6.0 – 4.6.5
Related vulnerabilities
Niewystarczające ograniczenia wywołań cURL w Couchbase Server (SQL++)
Niewystarczające ograniczenia wywołań cURL w /diag/eval w Couchbase Server
Wyciek metryk systemowych przez losowe żądania HTTP w Couchbase Server
Couchbase Server: Auth Bypass przez puste hasło użytkownika zewnętrznego
RCE w Couchbase Server przez ujawniony Erlang Cookie w logach