An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://forums.couchbase.com/tags/security | vendor advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | vendor advisory release notes |
https://www.couchbase.com/alerts | vendor advisory |