First published: Thu Mar 23 2023(Updated: )
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=6.6.0<7.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2023-28470 refers to an issue in Couchbase Server 5 through 7 before 7.1.4 where the nsstats endpoint is accessible without authentication.
Couchbase Server versions 5 through 7 before 7.1.4 are affected by CVE-2023-28470.
The severity of CVE-2023-28470 is medium with a CVSS score of 5.3.
To fix CVE-2023-28470, upgrade to Couchbase Server version 7.1.4 or later.
You can find more information about CVE-2023-28470 in the release notes, security forums, and alerts page provided by Couchbase.