← Vulnerability feed

Vulnerability record · CVE-2019-11495 · published 10 September 2019

CVE-2019-11495: Couchbase server vulnerability

Couchbase · Couchbase Server

In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small search space for potential random seeds that could then be used to brute force the cookie and execute code against a remote system. This has been fixed in version 6.0.0.

9.8 CVSS 3.1 Critical EPSS 2.1% · top 18.7% CWE-335 · CWE-335
9.8CVSS 3.1 base score, v2 7.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small search space for potential random seeds that could then be used to brute force the cookie and execute code against a remote system. This has been fixed in version 6.0.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11495 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-0519Google Chrome V8 out-of-bounds memory accessChrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger…KEVEPSS 3.8%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2023-2033Google Chrome V8 type confusion enables heap corruptionCVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap cor…KEVEPSS 41%analysed9.8CVE-2023-49930Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2023-49931Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2021-35943Couchbase server improper authentication vulnerabilityCouchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…EPSS 1.1%9.8CVE-2020-24719Couchbase server os command injection vulnerabilityExposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…EPSS 23%9.8CVE-2020-9039Couchbase server incorrect default permissions vulnerabilityCouchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2019-11495), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.