Vulnerability Details CVE-2020-9041
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack because they don't more aggressively terminate slow connections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-9041
-
cpe:2.3:a:couchbase:couchbase_server:6.0.3
-
cpe:2.3:a:couchbase:sync_gateway:2.1
-
cpe:2.3:a:couchbase:sync_gateway:2.1.0
-
cpe:2.3:a:couchbase:sync_gateway:2.1.1
-
cpe:2.3:a:couchbase:sync_gateway:2.1.2
-
cpe:2.3:a:couchbase:sync_gateway:2.1.3
-
cpe:2.3:a:couchbase:sync_gateway:2.5.0
-
cpe:2.3:a:couchbase:sync_gateway:2.6.0
-
cpe:2.3:a:couchbase:sync_gateway:2.7.0