PT-2019-12337 · Couchbase · Couchbase Server
Publicado
2019-09-10
·
Atualizado
2019-09-26
·
CVE-2019-11497
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Couchbase Server versions prior to 5.5.0
Description
The issue arises when an invalid Remote Cluster Certificate is entered as part of the reference creation in Couchbase Server. The server fails to parse and check the certificate signature, accepting the invalid certificate and attempting to use it for future connections to the remote cluster. This allows for potential exploitation. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For Couchbase Server versions prior to 5.5.0, update to version 5.5.0 or later to resolve the issue, as it includes a fix that thoroughly checks the validity of the certificate and prevents the creation of a remote cluster reference with an invalid certificate.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Couchbase Server