GHSA-g622-r636-qfqh

    Dashboard / Vulnerabilities / GHSA-g622-r636-qfqh

    GHSA-g622-r636-qfqh

    Published: 15 Feb 2022Last Modified: 8 Nov 2023
    Aliases:

    Summary: SQL Injection in Couchbase Sync Gateway

    Details: The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.

    Affected packages

    Package

    Name: github.com/couchbase/sync_gateway

    Purl: pkg:golang/github.com/couchbase/sync_gateway

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.5.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g622-r636-qfqh | CVE-DB