Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2x2-7857-rm23

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Couchbase Server 4.x and 5.x before 6.0.0 has Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).

Couchbase Server 4.x and 5.x before 6.0.0 has Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).

EPSS

Процентиль: 97%
0.30585
Средний

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

EPSS

Процентиль: 97%
0.30585
Средний

Дефекты

CWE-276