QID 730090
Date Published: 2021-06-07
QID 730090: Couchbase Sync Gateway Denial of service Vulnerability
Sync Gateway is the synchronization server in a Couchbase for Mobile and Edge deployment.
CVE-2020-9041: The Cluster Management and Views endpoints are vulnerable to the "Slowloris" denial-of-service attack as they don't more aggressively terminate slow connections.
Affected Products:
Couchbase Sync Gateway through 2.7.0
QID Detection Logic(Unauthenticated):
This QID sends a GET request and identify the vulnerable version of Couchbase sync Gateway.
Allows an attacker to take down a target web endpoint by sending requests that periodically send additional headers and never terminate.
Solution
Customers are advised to refer to Couchbase Sync Gateway for more information.
Vendor References
- Couchbase Sync Gateway -
www.couchbase.com/resources/security#SecurityAlerts
CVEs related to QID 730090
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Couchbase Sync Gateway |
|