An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://forums.couchbase.com/tags/security | issue tracking |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | release notes |
https://www.couchbase.com/alerts/ | vendor advisory |