Vulnerabilities
Vulnerable Software
Couchbase:  Security Vulnerabilities
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-07-12
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-06-14
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
CVSS Score
9.1
EPSS Score
0.007
Published
2022-06-14
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
CVSS Score
4.9
EPSS Score
0.005
Published
2022-06-14
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-06-13
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-06-13
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-06-13
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-06-13
An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-06-13
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
CVSS Score
6.5
EPSS Score
0.004
Published
2022-06-13


Contact Us

Shodan ® - All rights reserved