Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44rm-2q9r-5gjr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Couchbase Server 5.0.0. Editing bucket settings resets credentials, and leads to authorization without credentials.

An issue was discovered in Couchbase Server 5.0.0. Editing bucket settings resets credentials, and leads to authorization without credentials.

EPSS

Процентиль: 52%
0.00287
Низкий

Связанные уязвимости

CVSS3: 9.1
nvd
больше 6 лет назад

In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.

EPSS

Процентиль: 52%
0.00287
Низкий