CVE-2023-28470: Medium severity wut com-server highspeed 100baselx vulnerability
Published Mar 23, 2023
·Updated
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
Affected Software
1 affected component
Couchbase Couchbase Server>=6.6.0<7.1.4
Event History
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability CVE-2023-28470?
The vulnerability CVE-2023-28470 refers to an issue in Couchbase Server 5 through 7 before 7.1.4 where the nsstats endpoint is accessible without authentication.
2
What software is affected by CVE-2023-28470?
Couchbase Server versions 5 through 7 before 7.1.4 are affected by CVE-2023-28470.
3
What is the severity of CVE-2023-28470?
The severity of CVE-2023-28470 is medium with a CVSS score of 5.3.
4
How can I fix CVE-2023-28470?
To fix CVE-2023-28470, upgrade to Couchbase Server version 7.1.4 or later.
5
Where can I find more information about CVE-2023-28470?
You can find more information about CVE-2023-28470 in the release notes, security forums, and alerts page provided by Couchbase.