QID 730099

Date Published: 2021-06-01

QID 730099: Couchbase Server Sensitive Information Disclosure Vulnerability

Couchbase Server, originally known as Membase, is an open-source, distributed multi-model NoSQL document-oriented database software package optimized for interactive applications.

CVE-2021-25645: An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and stats.log files..

Affected Products:
Couchbase Server 5.5.0
Couchbase Server 6.6.0
Couchbase Server 6.5.1
Couchbase Server 6.5.0
Couchbase Server 6.0.4

QID Detection Logic(Unauthenticated):
This QID sends a GET request and identify the vulnerable version of Couchbase server on /versions.

Successful exploitation of this may vulnerability may allow an attacker to leak sensitive data like credentials in cleartext.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to Couchbase Server for more information.

    Vendor References

    CVEs related to QID 730099

    Software Advisories
    Advisory ID Software Component Link
    Couchbase Server URL Logo www.couchbase.com/resources/security#SecurityAlerts