Aller au contenu

Fiche vulnérabilité

CVE-2021-25644 : faille élevée couchbase couchbase server (CVSS 7.5)

Description

An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
19 mai 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • couchbase couchbase server

Références

Rechercher une autre vulnérabilité dans la base CVE