QID 730097

Date Published: 2021-06-01

QID 730097: Couchbase Server CSRF Vulnerability

Couchbase Server, originally known as Membase, is an open-source, distributed multi-model NoSQL document-oriented database software package optimized for interactive applications.

CVE-2020-9042: In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack.

Affected Products:
Couchbase Server 6.0.0

QID Detection Logic(Unauthenticated):
This QID sends a GET request and identify the vulnerable version of Couchbase server on /versions.

Successful exploitation of this vulnerability may allow an attacker to force the victim user to carry out an action unintentionally.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to Couchbase Server for more information.

    Vendor References

    CVEs related to QID 730097

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-9042 URL Logo www.couchbase.com/resources/security#SecurityAlerts