In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-3139 In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:55:40.205Z

Reserved: 2019-04-22T00:00:00

Link: CVE-2019-11466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-10T18:15:12.307

Modified: 2024-11-21T04:21:08.210

Link: CVE-2019-11466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.