Aller au contenu

Fiche vulnérabilité

CVE-2022-42951 : faille élevée couchbase couchbase server (CVSS 8.1)

Description

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
6 févr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • couchbase couchbase server

Références

Rechercher une autre vulnérabilité dans la base CVE