CVE-2020-9039 PoC — Couchbase Server 安全漏洞
关联漏洞
标题:
Couchbase Server 安全漏洞
(CVE-2020-9039)
Description:Couchbase Server是美国Couchbase公司的一款分布式的开源NoSQL(非关系型)数据库,它主要支持数据查询、全文检索和主动全局复制等功能。 Couchbase Server中存在安全漏洞。攻击者可利用该漏洞获取访问权限。以下产品及版本受到影响:4.0.0版本,4.1.0版本,4.1.1版本,4.5.0版本,4.5.1版本,4.6.0版本至4.6.5版本,5.0.0版本,5.1.1版本,5.5.0版本,5.5.1版本。
Description
Couchbase Server versions 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0-4.6.5, 5.0.0, 5.1.1, 5.5.0, and 5.5.1 contain insecure permissions for the projector and indexer REST endpoints caused by unauthenticated access, letting attackers access administrative APIs without authentication, exploit requires no special conditions.
文件快照
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →