In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://forums.couchbase.com/tags/security | vendor advisory |
https://www.couchbase.com/downloads | product |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | release notes |
https://www.couchbase.com/alerts/ | vendor advisory |