Server
by Couchbase
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56178 | Med | 0.42 | 6.5 | 0.00 | Jan 27, 2025 | An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role. | ||
| CVE-2023-45873 | Med | 0.42 | 6.5 | 0.01 | Feb 28, 2024 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer. | ||
| CVE-2022-32193 | Med | 0.42 | 6.5 | 0.01 | Jun 13, 2022 | Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. | ||
| CVE-2021-31158 | Med | 0.42 | 6.5 | 0.01 | May 19, 2021 | In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access. | ||
| CVE-2023-43769 | Med | 0.41 | 6.3 | 0.00 | Feb 29, 2024 | An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics. | ||
| CVE-2024-25673 | Med | 0.40 | 6.1 | 0.00 | Sep 19, 2024 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. | ||
| CVE-2019-11464 | Med | 0.40 | 6.1 | 0.01 | Sep 10, 2019 | Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for… | ||
| CVE-2024-37034 | Med | 0.38 | 5.9 | 0.00 | Jul 26, 2024 | An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure. | ||
| CVE-2022-34826 | Med | 0.38 | 5.9 | 0.01 | Jul 15, 2022 | In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. | ||
| CVE-2021-27924 | Med | 0.38 | 5.9 | 0.01 | May 19, 2021 | An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires. | ||
| CVE-2023-49932 | Med | 0.35 | 5.4 | 0.01 | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions. | ||
| CVE-2023-28470 | Med | 0.35 | 5.3 | 0.01 | Mar 23, 2023 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | ||
| CVE-2022-33911 | Med | 0.35 | 5.3 | 0.01 | Jul 12, 2022 | An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information. | ||
| CVE-2019-11466 | Med | 0.35 | 5.3 | 0.01 | Sep 10, 2019 | In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access. | ||
| CVE-2019-11465 | Med | 0.35 | 5.3 | 0.01 | Sep 10, 2019 | An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged… | ||
| CVE-2023-50436 | Med | 0.34 | 5.3 | 0.00 | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5. | ||
| CVE-2022-42950 | Med | 0.32 | 4.9 | 0.01 | Feb 6, 2023 | An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of… | ||
| CVE-2022-32561 | Med | 0.32 | 4.9 | 0.01 | Jun 14, 2022 | An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network. | ||
| CVE-2021-33504 | Med | 0.32 | 4.9 | 0.01 | Jun 2, 2022 | Couchbase Server before 7.1.0 has Incorrect Access Control. | ||
| CVE-2021-25643 | Med | 0.32 | 4.9 | 0.01 | May 26, 2021 | An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,… |
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.
- risk 0.42cvss 6.5epss 0.01
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
- risk 0.42cvss 6.5epss 0.01
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.
- risk 0.40cvss 6.1epss 0.00
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
- risk 0.40cvss 6.1epss 0.01
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for…
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
- risk 0.38cvss 5.9epss 0.01
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
- risk 0.35cvss 5.3epss 0.01
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
- risk 0.35cvss 5.3epss 0.01
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of…
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
- risk 0.32cvss 4.9epss 0.01
Couchbase Server before 7.1.0 has Incorrect Access Control.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,…
Page 3 of 4