Vulnerability Description
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for X-Permitted-Cross-Domain-Policies and X-XSS-Protection, which are more generally applicable to HTML endpoint, to be included too. These headers were not included in Couchbase Server 5.5.0 and 5.1.2 . They are now included in version 6.0.2 in responses from the Couchbase Server Views REST API (port 8092).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | Couchbase Server | 5.1.2 |
Related Weaknesses (CWE)
References
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
FAQ
What is CVE-2019-11464?
CVE-2019-11464 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some in...
How severe is CVE-2019-11464?
CVE-2019-11464 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11464?
Check the references section above for vendor advisories and patch information. Affected products include: Couchbase Couchbase Server.