{"api_version":"1","generated_at":"2026-07-23T20:58:44+00:00","cve":"CVE-2021-25644","urls":{"html":"https://cve.report/CVE-2021-25644","api":"https://cve.report/api/cve/CVE-2021-25644.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25644","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25644"},"summary":{"title":"CVE-2021-25644","description":"An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-05-19 19:15:00","updated_at":"2021-05-25 18:32:00"},"problem_types":["CWE-312"],"metrics":[],"references":[{"url":"https://www.couchbase.com/downloads","name":"https://www.couchbase.com/downloads","refsource":"MISC","tags":[],"title":"Best NoSQL Database | 30-Day Free Trial | Couchbase","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.couchbase.com/resources/security#SecurityAlerts","name":"https://www.couchbase.com/resources/security#SecurityAlerts","refsource":"MISC","tags":[],"title":"Enterprise-Level Security | Couchbase","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25644","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25644","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"25644","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"couchbase","cpe5":"couchbase_server","cpe6":"7.0.0","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"25644","vulnerable":"1","versionEndIncluding":"6.6.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"couchbase","cpe5":"couchbase_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-25644","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.couchbase.com/resources/security#SecurityAlerts","url":"https://www.couchbase.com/resources/security#SecurityAlerts"},{"url":"https://www.couchbase.com/downloads","refsource":"MISC","name":"https://www.couchbase.com/downloads"}]}},"nvd":{"publishedDate":"2021-05-19 19:15:00","lastModifiedDate":"2021-05-25 18:32:00","problem_types":["CWE-312"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:couchbase:couchbase_server:7.0.0:beta:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndIncluding":"6.6.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25644","Ordinal":"200456","Title":"CVE-2021-25644","CVE":"CVE-2021-25644","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25644","Ordinal":"1","NoteData":"An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"25644","Ordinal":"2","NoteData":"2021-05-19","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"25644","Ordinal":"3","NoteData":"2021-05-19","Type":"Other","Title":"Modified"}]}}}