SQL Injection in Couchbase Sync Gateway
Critical severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Reviewed
May 17, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Sep 18, 2023
The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.
References