CVE-2021-25644
Summary
| CVE | CVE-2021-25644 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-19 19:15:00 UTC |
| Updated | 2021-05-25 18:32:00 UTC |
| Description | An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Couchbase | Couchbase Server | 7.0.0 | beta | All | All |
| Application | Couchbase | Couchbase Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Best NoSQL Database | 30-Day Free Trial | Couchbase | MISC | www.couchbase.com | |
| Enterprise-Level Security | Couchbase | MISC | www.couchbase.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.