PT-2019-12326 · Couchbase · Couchbase Server
Published
2019-09-10
·
Updated
2020-08-24
·
CVE-2019-11466
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Couchbase Server versions 5.5.0 through 6.0.0
Description
The eventing service in Couchbase Server exposes system diagnostic profiles via an HTTP endpoint that does not require credentials on a port intended for internal traffic only.
Recommendations
For versions 5.5.0 through 6.0.0, update to version 6.0.1 or later to require valid credentials for accessing the system diagnostic profile.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Couchbase Server