CVE-2023-49931: Critical severity wut com-server highspeed 100baselx vulnerability
Published Feb 28, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
Affected Software
2 affected components
Couchbase Couchbase Server<7.2.4
Couchbase Couchbase Server>=5.0.0<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:41 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49931?
CVE-2023-49931 is considered a high-severity vulnerability due to inadequate restrictions on SQL++ cURL calls.
2
How do I fix CVE-2023-49931?
To fix CVE-2023-49931, upgrade Couchbase Server to version 7.2.4 or later.
3
What are the risks associated with CVE-2023-49931?
The risks associated with CVE-2023-49931 include unauthorized access and potential data manipulation through insecure SQL++ cURL calls.
4
Which versions of Couchbase Server are affected by CVE-2023-49931?
CVE-2023-49931 affects all versions of Couchbase Server prior to 7.2.4.
5
Is there a workaround for CVE-2023-49931?
Currently, the recommended solution for CVE-2023-49931 is to upgrade to a patched version, as no effective workaround is provided.