Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown
CVE-2021-37842
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
0
Attacker Value
Unknown
CVE-2021-42763
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.
0
Attacker Value
Unknown
CVE-2021-35945
Disclosure Date: September 29, 2021 (last updated November 28, 2024)
Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
0
Attacker Value
Unknown
CVE-2021-35944
Disclosure Date: September 29, 2021 (last updated November 28, 2024)
Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
0
Attacker Value
Unknown
CVE-2021-35943
Disclosure Date: September 29, 2021 (last updated November 28, 2024)
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
0
Attacker Value
Unknown
CVE-2021-25643
Disclosure Date: May 26, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens, /listRebalanceTokens, or /listMetadataTokens call.
0
Attacker Value
Unknown
CVE-2021-27924
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.
0
Attacker Value
Unknown
CVE-2021-25644
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
0
Attacker Value
Unknown
CVE-2021-31158
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
0
Attacker Value
Unknown
CVE-2021-27925
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.
0