Vulnerability Description
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | Couchbase Server | <= 5.0.0 |
Related Weaknesses (CWE)
References
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
FAQ
What is CVE-2019-11496?
CVE-2019-11496 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets inc...
How severe is CVE-2019-11496?
CVE-2019-11496 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11496?
Check the references section above for vendor advisories and patch information. Affected products include: Couchbase Couchbase Server.