CVE-2021-37842
Summary
| CVE | CVE-2021-37842 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-02 12:15:00 UTC |
| Updated | 2021-11-08 14:53:00 UTC |
| Description | metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Couchbase | Couchbase Server | 7.0.0 | - | All | All |
| Application | Couchbase | Couchbase Server | 7.0.1 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alerts | Couchbase | MISC | www.couchbase.com | |
| docs.couchbase.com/server/current/release-notes/relnotes.html | MISC | docs.couchbase.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.