QID 730089
Date Published: 2021-06-01
QID 730089: Couchbase Server Denial of service Vulnerability
Couchbase Server, originally known as Membase, is an open-source, distributed multi-model NoSQL document-oriented database software package optimized for interactive applications.
CVE-2020-9041: The Cluster Management and Views endpoints are vulnerable to the "Slowloris" denial-of-service attack as they don't more aggressively terminate slow connections.
Affected Products:
Couchbase Server 6.0.3
Couchbase Server 6.5.0
QID Detection Logic(Unauthenticated):
This QID sends a GET request and identify the vulnerable version of Couchbase server on /versions.
Allows an attacker to take down a target web endpoint by sending requests that periodically send additional headers and never terminate.
Customers are advised to refer to Couchbase Server for more information.
- Couchbase Server -
www.couchbase.com/resources/security#SecurityAlerts
CVEs related to QID 730089
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Couchbase Server |
|