First published: Wed May 19 2021(Updated: )
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=6.5.0<6.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-31158.
The title of this vulnerability is 'In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1 Common Table Expression queries not correctly checking user's permissions'.
The description of this vulnerability is 'Common Table Expression queries in Couchbase Server 6.5.x and 6.6.x through 6.6.1 did not correctly check the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access'.
Couchbase Server versions 6.5.x and 6.6.x through 6.6.1 are affected by this vulnerability.
The severity of CVE-2021-31158 is medium with a severity value of 6.5.
To fix the vulnerability identified as CVE-2021-31158, you should update Couchbase Server to version 6.6.2 or later, as this vulnerability has been fixed in that version.
Yes, you can find more information about this vulnerability at the following references: [1] [2]
The CWE ID associated with this vulnerability is CWE-863.