Couchbase Server - Broken Access Control
Couchbase Server versions 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0-4.6.5, 5.0.0, 5.1.1, 5.5.0, and 5.5.1 contain insecure permissions for the projector and indexer REST endpoints caused by unauthenticated access, letting attackers access administrative APIs without authentication, exploit requires no special conditions. References: https://docs.couchbase.com/server/current/index-rest-settings/index.html#Settings Remediation: Update to the latest version where the /settings REST endpoint requires authentication.
Used 3.2k times · 1 assets checked · url