CVE-2019-11466
10.09.2019, 18:15
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.Enginsight
Vendor | Product | Version |
---|---|---|
couchbase | couchbase_server | 5.5.0 |
couchbase | couchbase_server | 6.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration