Couchbase Server
by Couchbase
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33504 | Med | 0.32 | 4.9 | 0.01 | Jun 2, 2022 | Couchbase Server before 7.1.0 has Incorrect Access Control. | ||
| CVE-2021-25643 | Med | 0.32 | 4.9 | 0.01 | May 26, 2021 | An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,… | ||
| CVE-2021-27925 | Med | 0.29 | 4.4 | 0.01 | May 19, 2021 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked… | ||
| CVE-2021-25645 | Med | 0.29 | 4.4 | 0.00 | May 10, 2021 | An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and… | ||
| CVE-2023-45874 | Med | 0.28 | 4.3 | 0.01 | Feb 29, 2024 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads). |
- risk 0.32cvss 4.9epss 0.01
Couchbase Server before 7.1.0 has Incorrect Access Control.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,…
- risk 0.29cvss 4.4epss 0.01
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked…
- risk 0.29cvss 4.4epss 0.00
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
Page 3 of 3