PT-2020-20452 · Couchbase · Couchbase Server
Published
2020-02-22
·
Updated
2022-01-01
·
CVE-2020-9039
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Couchbase Server versions 4.0.0 through 4.6.5
Couchbase Server versions 5.0.0 through 5.5.1
Description
The issue concerns Insecure Permissions for the projector and indexer REST endpoints, allowing unauthenticated access. Specifically, the /settings REST endpoint, used by administrators for tasks like updating configuration and collecting performance profiles, was initially unauthenticated but has been updated to require authentication for access to these administrative APIs.
Recommendations
For Couchbase Server versions 4.0.0 through 4.6.5, update the configuration to only allow authenticated users to access the administrative APIs.
For Couchbase Server versions 5.0.0 through 5.5.1, update the configuration to only allow authenticated users to access the administrative APIs.
As a temporary workaround, consider restricting access to the
/settings REST endpoint until a patch is available.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Couchbase Server