An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
The /diag/eval endpoint in Couchbase Server enables execution of diagnostic code on the server. Due to insufficient restrictions on cURL calls directed to this endpoint, an attacker can send network requests without proper authentication or authorization. The vulnerability is classified as an access control issue (CWE-284), meaning that authorization verification mechanisms do not work as intended by security assumptions.
An attacker without any authentication, remotely over the network, can gain full control over the confidentiality, integrity, and availability of the system — corresponding to maximum CVSS scores in these categories.
Couchbase Server should be updated to version 7.2.4 or newer. Detailed information is available in the official release notes from the vendor at docs.couchbase.com and on the security alerts page at couchbase.com/alerts/
Couchbase Server in all versions before 7.2.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCouchbase Server
APPCouchbase7.1.5 – 7.2.4 (excl.)
Related vulnerabilities
Niewystarczające ograniczenia wywołań cURL w Couchbase Server (SQL++)
Wyciek metryk systemowych przez losowe żądania HTTP w Couchbase Server
Couchbase Server: Auth Bypass przez puste hasło użytkownika zewnętrznego
RCE w Couchbase Server przez ujawniony Erlang Cookie w logach
Couchbase Server – nieautoryzowany dostęp do endpointów REST projector i indexer