PT-2019-12326 · Couchbase · Couchbase Server
Publicado
2019-09-10
·
Atualizado
2020-08-24
·
CVE-2019-11466
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Couchbase Server versions 5.5.0 through 6.0.0
Description
The eventing service in Couchbase Server exposes system diagnostic profiles via an HTTP endpoint that does not require credentials on a port intended for internal traffic only.
Recommendations
For versions 5.5.0 through 6.0.0, update to version 6.0.1 or later to require valid credentials for accessing the system diagnostic profile.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Couchbase Server