← Back

CVE-2020-9039

Published: Feb 22, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

Affected (10)

1 product
Couchbase Server
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Couchbase
From 4.6.0 to 4.6.5
Version 4.0.0
Version 4.1.0
Version 4.1.1
Version 4.5.0
Version 4.5.1
Version 5.0.0
Version 5.1.1
Version 5.5.0
Version 5.5.1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.