CVE-2020-9040: High severity couchbase server vulnerability
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9040?
CVE-2020-9040 is a vulnerability in the Couchbase Server Java SDK that allows an attacker to forge an SSL certificate and pose as the intended peer.
How does CVE-2020-9040 work?
An attacker can exploit CVE-2020-9040 by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.
What is the severity of CVE-2020-9040?
CVE-2020-9040 has a severity rating of 7.5 (High).
What is the affected software for CVE-2020-9040?
The affected software is Couchbase Server Java SDK versions between 1.7.1 and 2.7.1.1.
How can I fix CVE-2020-9040?
To fix CVE-2020-9040, it is recommended to upgrade to Couchbase Server Java SDK version 2.7.1.1 or later.