Vulnerability Details CVE-2021-35943
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-35943
-
cpe:2.3:a:couchbase:couchbase_server:6.5.0
-
cpe:2.3:a:couchbase:couchbase_server:6.5.1
-
cpe:2.3:a:couchbase:couchbase_server:6.5.2
-
cpe:2.3:a:couchbase:couchbase_server:6.6.0
-
cpe:2.3:a:couchbase:couchbase_server:6.6.1
-
cpe:2.3:a:couchbase:couchbase_server:6.6.2