CVE-2019-11496: Critical severity wut com-server highspeed 100baselx vulnerability
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Couchbase Server vulnerability?
The vulnerability ID for the Couchbase Server vulnerability is CVE-2019-11496.
What is the severity level of CVE-2019-11496?
The severity level of CVE-2019-11496 is critical with a score of 9.1.
Which versions of Couchbase Server are affected by CVE-2019-11496?
Versions of Couchbase Server prior to 5.0 are affected by CVE-2019-11496.
What was the behavior of the "default" bucket in versions prior to 5.0?
In versions prior to 5.0, the "default" bucket allowed read and write access without authentication.
How was the behavior of all buckets changed in version 5.0?
In version 5.0, the behavior of all buckets, including the "default" bucket, was changed to only allow access by authenticated users with sufficient authorization.
How can I fix the vulnerability in my Couchbase Server?
To fix the vulnerability, upgrade your Couchbase Server to a version later than 5.0.