Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Couchbase Server HIGH 7.5
CVE-2022-32564

An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.

Fix: 7.0.4+
Fix from $1,950 2022-06-13
Couchbase Server HIGH 7.5
CVE-2022-32558

An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.

Fix: after 6.6.3
Fix from $1,950 2022-06-13
Couchbase Server MEDIUM 6.5
CVE-2022-32193

Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

Fix: after 6.6.3
Fix from $1,600 2022-06-13
Sync Gateway CRITICAL 9.8
CVE-2022-32563

An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentica…

Fix: 3.0.2+
Fix from $2,300 2022-06-10
Bleve MEDIUM 5.5
CVE-2022-31022

Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP …

Patch available
Fix from $1,600 2022-06-01
Cloud Native Operator HIGH 7.5
CVE-2022-26311

Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted in logs collected from Kuberne…

Fix: 2.2.3+
Fix from $1,950 2022-03-10
Sync Gateway HIGH 8.1
CVE-2021-43963

An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were in…

Fix: 2.8.3+
Fix from $1,950 2021-12-07
Couchbase Server HIGH 7.5
CVE-2021-37842

metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. C…

Mitigation only
Fix from $1,950 2021-11-02
Couchbase Server HIGH 7.5
CVE-2021-42763

Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HT…

Fix: 4.6.0 / 6.1.0+
Fix from $1,950 2021-11-02
Couchbase Server CRITICAL 9.8
CVE-2021-35943

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…

Fix: 6.6.3+
Fix from $2,300 2021-09-29
Couchbase Server HIGH 7.5
CVE-2021-35944

Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memc…

Fix: after 6.6.2
Fix from $1,950 2021-09-29
Couchbase Server HIGH 7.5
CVE-2021-35945

Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash mem…

Fix: after 6.6.2
Fix from $1,950 2021-09-29
Couchbase Server MEDIUM 5.9
CVE-2021-27924

An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows…

Fix: 6.6.2+
Fix from $1,600 2021-05-19
Couchbase Server HIGH 7.5
CVE-2021-25644

An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authent…

Fix: after 6.6.1
Fix from $1,950 2021-05-19
Couchbase Server MEDIUM 6.5
CVE-2021-31158

In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permiss…

Fix: 6.6.2+
Fix from $1,600 2021-05-19
Couchbase Server CRITICAL 9.8
CVE-2020-24719EPSS 23%

Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…

Fix: 6.6.0+
Fix from $2,300 2020-11-12
Couchbase Server HIGH 8.8
CVE-2020-9042

In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the…

Mitigation only
Fix from $1,950 2020-06-08
Couchbase Server Java Sdk HIGH 7.5
CVE-2020-9040

Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can lever…

Fix: 2.7.1.1+
Fix from $1,950 2020-06-08
Couchbase Server HIGH 7.5
CVE-2020-9041

In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerab…

Fix: after 2.7.0
Fix from $1,950 2020-06-08
Couchbase Server CRITICAL 9.8
CVE-2020-9039

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an…

Fix: after 4.6.5
Fix from $2,300 2020-02-22
Couchbase Server CRITICAL 9.8
CVE-2019-11495

In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR…

Mitigation only
Fix from $2,300 2019-09-10
Couchbase Server CRITICAL 9.1
CVE-2019-11496

In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authenticati…

Fix: after 5.0.0
Fix from $2,300 2019-09-10
Couchbase Server HIGH 7.5
CVE-2019-11467

In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries contain certain chara…

Mitigation only
Fix from $1,950 2019-09-10
Couchbase Server HIGH 7.5
CVE-2019-11497

In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the…

Mitigation only
Fix from $1,950 2019-09-10
Couchbase Server MEDIUM 5.3
CVE-2019-11466

In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on…

Mitigation only
Fix from $1,600 2019-09-10
Couchbase Server MEDIUM 6.1
CVE-2019-11464

Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Ty…

Mitigation only
Fix from $1,600 2019-09-10
Couchbase Server MEDIUM 5.3
CVE-2019-11465

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted userna…

Fix: after 5.5.3
Fix from $1,600 2019-09-10
Sync Gateway CRITICAL 9.8
CVE-2019-9039

In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extra…

No fix yet
Fix from $2,300 2019-06-26
Couchbase Server HIGH 8.8
CVE-2018-15728

Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad…

No fix yet
Fix from $1,950 2018-08-24