CRITICAL9.8
GHSA-g622-r636-qfqh
SQL Injection in Couchbase Sync Gateway
Quick fix
GHSA-g622-r636-qfqh — github.com/couchbase/sync_gateway: upgrade to the fixed version with the command below.
go get github.com/couchbase/sync_gateway@v2.5.0Details
The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/couchbase/sync_gateway
Introduced in:
0Fixed in: 2.5.0Fix
go get github.com/couchbase/sync_gateway@v2.5.0References
- https://nvd.nist.gov/vuln/detail/CVE-2019-9039[ADVISORY]
- https://github.com/couchbase/sync_gateway/commit/97adb5b496aa96aa70398018ea96da913ffd8d8c[WEB]
- https://docs.couchbase.com/sync-gateway/2.5/release-notes.html[WEB]
- https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039[WEB]
- https://www.couchbase.com/resources/security#SecurityAlerts[WEB]