PT-2024-13137 · Couchbase · Couchbase Server

Published

2024-02-28

·

Updated

2025-04-08

·

CVE-2023-43769

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Couchbase Server versions through 7.1.4 before 7.1.5 and before 7.2.1
Description An issue was discovered in Couchbase Server where Unauthenticated RMI Service Ports are Exposed in Analytics, posing a significant risk. This could allow an attacker to escalate privileges.
Recommendations For versions through 7.1.4 before 7.1.5 and before 7.2.1, update to version 7.1.5 or 7.2.1 to resolve the issue. As a temporary workaround, consider restricting access to the Analytics Service to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2023-43769

Affected Products

Couchbase Server