In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
References
Link | Resource |
---|---|
https://www.couchbase.com/resources/security#SecurityAlerts | Vendor Advisory |
https://www.couchbase.com/resources/security#SecurityAlerts | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.couchbase.com/resources/security#SecurityAlerts - Vendor Advisory |
Information
Published : 2019-09-10 18:15
Updated : 2024-11-21 04:21
NVD link : CVE-2019-11466
Mitre link : CVE-2019-11466
CVE.ORG link : CVE-2019-11466
JSON object : View
Products Affected
couchbase
- couchbase_server
CWE
CWE-306
Missing Authentication for Critical Function