{"id":"CVE-2019-9039","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-9039","summary":"SQL Injection in Couchbase Sync Gateway","details":"The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.","published":"2022-02-15T01:57:18Z","modified":"2023-11-08T04:01:46.370526Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/couchbase/sync_gateway","fixedVersion":"2.5.0"}],"fix":{"url":"https://github.com/couchbase/sync_gateway/commit/97adb5b496aa96aa70398018ea96da913ffd8d8c","label":"couchbase/sync_gateway@97adb5b"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9039"},{"type":"WEB","url":"https://github.com/couchbase/sync_gateway/commit/97adb5b496aa96aa70398018ea96da913ffd8d8c"},{"type":"WEB","url":"https://docs.couchbase.com/sync-gateway/2.5/release-notes.html"},{"type":"WEB","url":"https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039"},{"type":"WEB","url":"https://www.couchbase.com/resources/security#SecurityAlerts"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:01:46.370526Z"}}