VYPR

Couchbase Server

by Couchbase

CVEs (45)

  • CVE-2021-33504MedJun 2, 2022
    risk 0.32cvss 4.9epss 0.01

    Couchbase Server before 7.1.0 has Incorrect Access Control.

  • CVE-2021-25643MedMay 26, 2021
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,…

  • CVE-2021-27925MedMay 19, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked…

  • CVE-2021-25645MedMay 10, 2021
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and…

  • CVE-2023-45874MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

Page 3 of 3