AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-9039

CRITICAL · CVSS 9.8 EPSS 3.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-22 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-9039
Severity
CRITICAL
CVSS
9.8
EPSS
3.94%

Original NVD Description

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

Related CVEs

Other vulnerabilities affecting the same vendor(s)