CVE-2021-25644
Published May 19, 2021
Last updated 3 years ago
Overview
- Description
- An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-312
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDB439D8-9F76-4071-91D7-DBC635DA029F", "versionEndIncluding": "6.6.1", "versionStartIncluding": "5.0.0" }, { "criteria": "cpe:2.3:a:couchbase:couchbase_server:7.0.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF1669E5-DA58-4B59-A474-385D46D82510" } ], "operator": "OR" } ] } ]