CVE-2020-9039: Critical severity Couchbase Couchbase Server vulnerability
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.0.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.1.1 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.5.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.5.1 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.6.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 4.6.5 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 5.0.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 5.1.1 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 5.5.0 - Upgrade
Upgrade
Couchbase Serverto a version that resolves this vulnerability.Fixed in 5.5.1
Event History
Frequently Asked Questions
What is CVE-2020-9039?
CVE-2020-9039 is a vulnerability in Couchbase Server that allows unauthenticated access to the projector and indexer REST endpoints.
Which versions of Couchbase Server are affected by CVE-2020-9039?
Couchbase Server versions 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0, and 5.5.1 are affected by CVE-2020-9039.
What is the severity of CVE-2020-9039?
CVE-2020-9039 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2020-9039?
To fix CVE-2020-9039, you should upgrade your Couchbase Server to a version that includes the necessary security patches.
Where can I find more information about CVE-2020-9039?
You can find more information about CVE-2020-9039 on the Couchbase website's security alerts page.