CVE-2023-49932: Medium severity wut com-server highspeed 100baselx vulnerability
Published Feb 28, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
Affected Software
2 affected components
Couchbase Couchbase Server<7.2.4
Couchbase Couchbase Server>=5.0.0<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:41 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49932?
CVE-2023-49932 has a moderate severity rating due to the potential for SQL++ N1QL cURL host restriction bypass.
2
How do I fix CVE-2023-49932?
To fix CVE-2023-49932, update Couchbase Server to version 7.2.4 or later.
3
What versions of Couchbase Server are affected by CVE-2023-49932?
CVE-2023-49932 affects all versions of Couchbase Server prior to 7.2.4.
4
What is the impact of exploiting CVE-2023-49932?
Exploiting CVE-2023-49932 allows attackers to bypass security restrictions on SQL++ N1QL queries.
5
Is there a workaround for CVE-2023-49932?
Currently, the recommended action for CVE-2023-49932 is to apply the available patch by upgrading to the fixed version.