QID 379651
QID 379651: Couchbase Server Improper Authentication Vulnerability (CVE-2023-49338)
Couchbase Server, originally known as Membase, is an open-source, distributed multi-model NoSQL document-oriented database software package optimized for interactive applications.
CVE-2023-49338: The Query stats endpoint did not implement correct authentication, making it possible to view the stats information.
Affected Products:
Couchbase Server 7.2.3
Couchbase Server 7.2.2
Couchbase Server 7.2.1
Couchbase Server 7.2.0
All 7.1 versions
All 7.0 versions
All 6 versions
All 5 versions
All 4 version
QID Detection Logic(Authenticated):
QID checks for vulnerable versions of installed Couchbase server in the System.
Successful exploitation of this vulnerability could make it possible to view the stats information without authentication.
- Couchbase Server -
www.couchbase.com/alerts/
CVEs related to QID 379651
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Couchbase Server |
|