Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-32558
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
0
Attacker Value
Unknown
CVE-2022-32193
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
0
Attacker Value
Unknown
CVE-2021-37842
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
0
Attacker Value
Unknown
CVE-2021-42763
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.
0
Attacker Value
Unknown
CVE-2021-35945
Disclosure Date: September 29, 2021 (last updated November 28, 2024)
Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
0
Attacker Value
Unknown
CVE-2021-35944
Disclosure Date: September 29, 2021 (last updated November 28, 2024)
Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
0
Attacker Value
Unknown
CVE-2021-25644
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
0