PT-2019-12337 · Couchbase · Couchbase Server

Published

2019-09-10

·

Updated

2019-09-26

·

CVE-2019-11497

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Couchbase Server versions prior to 5.5.0
Description The issue arises when an invalid Remote Cluster Certificate is entered as part of the reference creation in Couchbase Server. The server fails to parse and check the certificate signature, accepting the invalid certificate and attempting to use it for future connections to the remote cluster. This allows for potential exploitation. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For Couchbase Server versions prior to 5.5.0, update to version 5.5.0 or later to resolve the issue, as it includes a fix that thoroughly checks the validity of the certificate and prevents the creation of a remote cluster reference with an invalid certificate.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11497

Affected Products

Couchbase Server