Couchbase Server vulnerabilities
62 known vulnerabilities affecting couchbase/couchbase_server.
Total CVEs
62
CISA KEV
3
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH31MEDIUM23
Vulnerabilities
Page 4 of 4
CVE-2019-11464MEDIUMCVSS 6.1v5.1.2v5.5.02019-09-10
CVE-2019-11464 [MEDIUM] CWE-79 CVE-2019-11464: Some enterprises require that REST API endpoints include security-related headers in REST responses.
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for X-Permitted-Cross-Domain-Policies and X-XSS-Protection, which are more generally applicable to HT
nvd
CVE-2019-11466MEDIUMCVSS 5.3v5.5.0v6.0.02019-09-10
CVE-2019-11466 [MEDIUM] CWE-306 CVE-2019-11466: In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an H
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
nvd
← Previous4 / 4