Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-19325

XDCR server name verification not effective in SSL over MEM mode

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 4.5.0
    • 4.0.0, 4.1.0, 4.5.0
    • XDCR
    • None
    • Untriaged
    • Unknown

    Description

      In SSL replication, when target cluster is of version 4.0 and up, XDCR attempts to do server name check in tls handshake. This is done incorrectly, though, and the server name check is effectively skipped. This creates an unnecessary vulnerability that needs to be fixed.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            yu Yu Sui (Inactive)
            yu Yu Sui (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty