GHSA-g622-r636-qfqh
Dashboard / Vulnerabilities / GHSA-g622-r636-qfqh
Summary: SQL Injection in Couchbase Sync Gateway
Details: The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-9039, https://github.com/couchbase/sync_gateway/commit/97adb5b496aa96aa70398018ea96da913ffd8d8c, https://docs.couchbase.com/sync-gateway/2.5/release-notes.html, https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039, https://www.couchbase.com/resources/security#SecurityAlerts
Affected packages
Package
Name: github.com/couchbase/sync_gateway
Purl: pkg:golang/github.com/couchbase/sync_gateway
Affected ranges
Type: SEMVER
Events:
