CVE-2019-9039
Last modified
CVE-2019-9039 is a vulnerability of currently unknown severity. In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. EPSS estimates a 2.74% chance of exploitation in the next 30 days.
Description
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication and external access to this REST endpoint has been blocked to mitigate this issue. This issue has been fixed in versions 2.5.0 and 2.1.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | Sync Gateway | 2.1.2 |
References
- https://docs.couchbase.com/sync-gateway/2.5/release-notes.htmlRelease Notes, Vendor Advisory
- https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039/Exploit, Third Party Advisory
- https://docs.couchbase.com/sync-gateway/2.5/release-notes.htmlRelease Notes, Vendor Advisory
- https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9039?
How severe is CVE-2019-9039?
How do I fix CVE-2019-9039?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9033An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9034An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9035An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9036An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9037An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9038An issue was discovered in libmatio.a in matio (aka MAT File…
- CVE-2019-9040S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin u…
- CVE-2019-9041An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/…
- CVE-2019-9042An issue was discovered in Sitemagic CMS v4.4. In the index.…
- CVE-2019-9047GoRose v1.0.4 has SQL Injection when the order_by or group_b…
- CVE-2019-9048An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF…
- CVE-2019-9049An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF…
Are you affected by CVE-2019-9039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
