PT-2019-12335 · Couchbase · Couchbase Server

CVE-2019-11495

·

Published

2019-09-10

·

Updated

2024-02-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Couchbase Server versions prior to 6.0.0
Description The issue arises from the insecure generation of a cookie used for intra-node communication in Couchbase Server. Specifically, the erlang:now() function is used to seed the PRNG, resulting in a limited search space for potential random seeds. This could allow an attacker to brute force the cookie and execute code against a remote system.
Recommendations For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11495

Affected Products

Couchbase Server