CRITICAL🇵🇱 Wersja polska

CVE-2023-49931

CVSS 9.8v3.1pub. 2024-02-29upd. 2025-04-08

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

🤖 AI Analysis
How it works

The /diag/eval endpoint in Couchbase Server is used to execute server-side code for diagnostic purposes. Insufficient restrictions on cURL calls initiated by SQL++ queries allow an attacker to send requests to this endpoint without proper authorization. As a result, it is possible to bypass access control mechanisms (CWE-284 — Improper Access Control) and interact with the protected diagnostic interface.

Impact

An unauthenticated attacker can gain full control over the server, including disclosure of sensitive data, data modification, and potentially disruption of service availability.

Mitigation & patch

Couchbase Server must be updated to version 7.2.4 or later. Detailed information is available in the vendor's release notes at docs.couchbase.com/server/current/release-notes/relnotes.html and on the security alerts page at couchbase.com/alerts/

Who is affected

Couchbase Server in all versions before 7.2.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Couchbase Server

    APP
    Couchbase
    5.0.0 – 7.2.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-49930CRITICAL9.8PL ✓same product

Niewystarczające ograniczenia wywołań cURL w /diag/eval w Couchbase Server

CVE-2022-32559CRITICAL9.1PL ✓same product

Wyciek metryk systemowych przez losowe żądania HTTP w Couchbase Server

CVE-2021-35943CRITICAL9.8PL ✓same product

Couchbase Server: Auth Bypass przez puste hasło użytkownika zewnętrznego

CVE-2020-24719CRITICAL9.8PL ✓same product

RCE w Couchbase Server przez ujawniony Erlang Cookie w logach

CVE-2020-9039CRITICAL9.8PL ✓same product

Couchbase Server – nieautoryzowany dostęp do endpointów REST projector i indexer