Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11496

Опубликовано: 10 сент. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
Версия до 5.0.0 (включая)

EPSS

Процентиль: 52%
0.00287
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in Couchbase Server 5.0.0. Editing bucket settings resets credentials, and leads to authorization without credentials.

EPSS

Процентиль: 52%
0.00287
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-306