VDB
Sign up
CRITICAL9.8

GHSA-g622-r636-qfqh

SQL Injection in Couchbase Sync Gateway

Quick fix

GHSA-g622-r636-qfqh — github.com/couchbase/sync_gateway: upgrade to the fixed version with the command below.

go get github.com/couchbase/sync_gateway@v2.5.0

Details

The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/couchbase/sync_gateway
Introduced in: 0Fixed in: 2.5.0
Fixgo get github.com/couchbase/sync_gateway@v2.5.0

References