{"id":"GHSA-g622-r636-qfqh","summary":"SQL Injection in Couchbase Sync Gateway","details":"The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.","aliases":["CVE-2019-9039"],"modified":"2023-11-08T04:01:46.370526Z","published":"2022-02-15T01:57:18Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-05-17T16:33:43Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9039"},{"type":"WEB","url":"https://github.com/couchbase/sync_gateway/commit/97adb5b496aa96aa70398018ea96da913ffd8d8c"},{"type":"WEB","url":"https://docs.couchbase.com/sync-gateway/2.5/release-notes.html"},{"type":"WEB","url":"https://research.hisolutions.com/2019/06/n1ql-injection-in-couchbase-sync-gateway-cve-2019-9039"},{"type":"WEB","url":"https://www.couchbase.com/resources/security#SecurityAlerts"}],"affected":[{"package":{"name":"github.com/couchbase/sync_gateway","ecosystem":"Go","purl":"pkg:golang/github.com/couchbase/sync_gateway"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-g622-r636-qfqh/GHSA-g622-r636-qfqh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}