An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
The /diag/eval endpoint in Couchbase Server is used to execute server-side code for diagnostic purposes. Insufficient restrictions on cURL calls initiated by SQL++ queries allow an attacker to send requests to this endpoint without proper authorization. As a result, it is possible to bypass access control mechanisms (CWE-284 — Improper Access Control) and interact with the protected diagnostic interface.
An unauthenticated attacker can gain full control over the server, including disclosure of sensitive data, data modification, and potentially disruption of service availability.
Couchbase Server must be updated to version 7.2.4 or later. Detailed information is available in the vendor's release notes at docs.couchbase.com/server/current/release-notes/relnotes.html and on the security alerts page at couchbase.com/alerts/
Couchbase Server in all versions before 7.2.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCouchbase Server
APPCouchbase5.0.0 – 7.2.4 (excl.)
Related vulnerabilities
Niewystarczające ograniczenia wywołań cURL w /diag/eval w Couchbase Server
Wyciek metryk systemowych przez losowe żądania HTTP w Couchbase Server
Couchbase Server: Auth Bypass przez puste hasło użytkownika zewnętrznego
RCE w Couchbase Server przez ujawniony Erlang Cookie w logach
Couchbase Server – nieautoryzowany dostęp do endpointów REST projector i indexer