← Vulnerability feed

Vulnerability record · CVE-2020-24719 · published 12 November 2020

CVE-2020-24719: Couchbase server os command injection vulnerability

Couchbase · Couchbase Server

Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS level commands on the system running the Erlang node. Affects version: 6.5.1. Fix version: 6.6.0.

9.8 CVSS 3.1 Critical EPSS 23% · top 2.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS level commands on the system running the Erlang node. Affects version: 6.5.1. Fix version: 6.6.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24719 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-0519Google Chrome V8 out-of-bounds memory accessChrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger…KEVEPSS 3.8%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2023-2033Google Chrome V8 type confusion enables heap corruptionCVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap cor…KEVEPSS 41%analysed9.8CVE-2023-49930Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2023-49931Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2021-35943Couchbase server improper authentication vulnerabilityCouchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…EPSS 1.1%9.8CVE-2020-9039Couchbase server incorrect default permissions vulnerabilityCouchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an…EPSS 3.9%9.8CVE-2019-11495Couchbase server vulnerabilityIn Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2020-24719), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.