9.8
CVSSv3

CVE-2020-9039

Published: 22/02/2020 Updated: 01/01/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 up to and including 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

couchbase couchbase server 4.0.0

couchbase couchbase server 4.1.0

couchbase couchbase server 4.1.1

couchbase couchbase server 4.5.0

couchbase couchbase server 4.5.1

couchbase couchbase server

couchbase couchbase server 5.0.0

couchbase couchbase server 5.1.1

couchbase couchbase server 5.5.0

couchbase couchbase server 5.5.1