GHSA-g622-r636-qfqh
CRITICALCVE-2019-9039The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?alldocs? endpoint.
- Affected
- < 2.5.0
- Fixed in
- 2.5.0
- Weakness
- CWE-89
- Published
- 2022-02-15
- Source
- github