CVE-2019-11496Missing Authentication for Critical Function in Server

Severity
9.1CRITICALNVD
EPSS
0.3%
top 47.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateMay 24

Description

In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-44rm-2q9r-5gjr: An issue was discovered in Couchbase Server 52022-05-24
CVEList
CVE-2019-11496: In versions of Couchbase Server prior to 52019-09-10
CVE-2019-11496 — Couchbase Server vulnerability | cvebase