Vulnerabilities > Couchbase > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-29 CVE-2021-35943 Improper Authentication vulnerability in Couchbase Server
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.
network
low complexity
couchbase CWE-287
7.5
2020-02-22 CVE-2020-9039 Incorrect Default Permissions vulnerability in Couchbase Server
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles.
network
low complexity
couchbase CWE-276
7.5
2019-09-10 CVE-2019-11467 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Couchbase Server 4.6.3/5.5.0
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.
network
low complexity
couchbase CWE-119
7.8
2019-06-26 CVE-2019-9039 SQL Injection vulnerability in Couchbase Sync Gateway 2.1.2
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint.
network
low complexity
couchbase CWE-89
7.5