This page lists critical alerts and advisories for Couchbase.
Stay informed about the latest critical alerts and advisories for Couchbase Server by subscribing to our update notifications. To sign up, please register on our support site and follow this article: Announcements – Couchbase Support
Enterprise Security Alerts
-
Update of openssl to 1.1.1o
Updated openssl to fix a flaw in an openssl component, c_rehash. This script scans directories and takes a hash value of each .pem and .crt file in the directory. It then creates symbolic links for each of the files named by the hash value. It has a flaw that allows command injection in the script.
-
Credential Disclosure Vulnerability in Sync Gateway Log Collection Process
A security vulnerability was identified in Sync Gateway that, in certain situations, resulted in the unintentional disclosure of credentials associated with log collection for support. This affected the set of credentials used to initiate the log collection process. We recommend upgrading to Sync Gateway 3.2.6, which addresses this issue, and rotating any credentials that were used to initiate log collection during the affected period.
-
.NET SDK v3.7.1 and prior could skip certificate hostname verification
In .NET SDK v3.7.1 and earlier, hostname verification for TLS certificates was not properly enforced in all cases.
-
Upgrade Bouncy Castle to 1.79
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
-
Update JDK to 17.0.13
This vulnerability is challenging to exploit but allows an unauthenticated attacker with network access via multiple protocols to potentially compromise the affected products. Successful exploitation could result in unauthorized updates, insertions, or deletions of accessible data, as well as unauthorized read access to certain data subsets.
-
Local File Inclusion Vulnerability identified in Couchbase Server for Windows
A security issue has been discovered in Couchbase Server for Windows that could allow unauthorized access to sensitive files on the system. Depending on the level of privileges, this vulnerability may grant access to files such as / etc / passwd or / etc / shadow.