CVE-2023-49930: Critical severity couchbase vulnerability
Published Feb 28, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Affected Software
2 affected components
Couchbase Server<7.2.4
Couchbase Couchbase Server>=7.1.5<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:41 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49930?
CVE-2023-49930 is considered a medium severity vulnerability due to insufficient restrictions on cURL calls to the /diag/eval endpoint.
2
How do I fix CVE-2023-49930?
To fix CVE-2023-49930, upgrade Couchbase Server to version 7.2.4 or later.
3
What software is affected by CVE-2023-49930?
CVE-2023-49930 affects Couchbase Server versions prior to 7.2.4.
4
What are the potential risks associated with CVE-2023-49930?
The potential risks of CVE-2023-49930 include unauthorized access to sensitive diagnostic information and potential exploitation by an attacker.
5
When was CVE-2023-49930 disclosed?
CVE-2023-49930 was disclosed in 2023 and affects earlier versions of Couchbase Server.