Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Couchbase_server
(Couchbase)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 44 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-09-10 | CVE-2019-11495 | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small search space for potential random seeds that could then be used to brute force the cookie and execute code against a remote system. This has been fixed in version 6.0.0. | Couchbase_server | 9.8 | ||
2023-11-08 | CVE-2023-45875 | An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. | Couchbase_server | 7.5 | ||
2023-11-08 | CVE-2023-36667 | Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. | Couchbase_server | 7.5 | ||
2022-06-02 | CVE-2021-33504 | Couchbase Server before 7.1.0 has Incorrect Access Control. | Couchbase_server | 4.9 | ||
2022-06-13 | CVE-2022-32560 | An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. | Couchbase_server | 7.5 | ||
2022-06-14 | CVE-2022-32557 | An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. | Couchbase_server | 7.5 | ||
2022-06-14 | CVE-2022-32559 | An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. | Couchbase_server | 9.1 | ||
2022-07-15 | CVE-2022-34826 | In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. | Couchbase_server | 5.9 | ||
2023-02-06 | CVE-2022-42951 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials. | Couchbase_server | 8.1 | ||
2023-03-23 | CVE-2023-28470 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | Couchbase_server | 5.3 |