Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-32564 An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie. Couchbase Server 7.0.4+ Fix from $1,9502022-06-13 HIGH 7.5 CVE-2022-32558 An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure. Couchbase Server after 6.6.3 Fix from $1,9502022-06-13 MEDIUM 6.5 CVE-2022-32193 Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. Couchbase Server after 6.6.3 Fix from $1,6002022-06-13 CRITICAL 9.8 CVE-2022-32563 An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentica… Sync Gateway 3.0.2+ Fix from $2,3002022-06-10 MEDIUM 5.5 CVE-2022-31022 Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP … Bleve Patch available Fix from $1,6002022-06-01 HIGH 7.5 CVE-2022-26311 Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted in logs collected from Kuberne… Cloud Native Operator 2.2.3+ Fix from $1,9502022-03-10 HIGH 8.1 CVE-2021-43963 An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were in… Sync Gateway 2.8.3+ Fix from $1,9502021-12-07 HIGH 7.5 CVE-2021-37842 metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. C… Couchbase Server Mitigation only Fix from $1,9502021-11-02 HIGH 7.5 CVE-2021-42763 Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HT… Couchbase Server 4.6.0 / 6.1.0+ Fix from $1,9502021-11-02 CRITICAL 9.8 CVE-2021-35943 Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,… Couchbase Server 6.6.3+ Fix from $2,3002021-09-29 HIGH 7.5 CVE-2021-35944 Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memc… Couchbase Server after 6.6.2 Fix from $1,9502021-09-29 HIGH 7.5 CVE-2021-35945 Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash mem… Couchbase Server after 6.6.2 Fix from $1,9502021-09-29 MEDIUM 5.9 CVE-2021-27924 An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows… Couchbase Server 6.6.2+ Fix from $1,6002021-05-19 HIGH 7.5 CVE-2021-25644 An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authent… Couchbase Server after 6.6.1 Fix from $1,9502021-05-19 MEDIUM 6.5 CVE-2021-31158 In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permiss… Couchbase Server 6.6.2+ Fix from $1,6002021-05-19 CRITICAL 9.8 CVE-2020-24719EPSS 23% Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (… Couchbase Server 6.6.0+ Fix from $2,3002020-11-12 HIGH 8.8 CVE-2020-9042 In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the… Couchbase Server Mitigation only Fix from $1,9502020-06-08 HIGH 7.5 CVE-2020-9040 Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can lever… Couchbase Server Java Sdk 2.7.1.1+ Fix from $1,9502020-06-08 HIGH 7.5 CVE-2020-9041 In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerab… Couchbase Server after 2.7.0 Fix from $1,9502020-06-08 CRITICAL 9.8 CVE-2020-9039 Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an… Couchbase Server after 4.6.5 Fix from $2,3002020-02-22 CRITICAL 9.8 CVE-2019-11495 In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR… Couchbase Server Mitigation only Fix from $2,3002019-09-10 CRITICAL 9.1 CVE-2019-11496 In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authenticati… Couchbase Server after 5.0.0 Fix from $2,3002019-09-10 HIGH 7.5 CVE-2019-11467 In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries contain certain chara… Couchbase Server Mitigation only Fix from $1,9502019-09-10 HIGH 7.5 CVE-2019-11497 In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the… Couchbase Server Mitigation only Fix from $1,9502019-09-10 MEDIUM 5.3 CVE-2019-11466 In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on… Couchbase Server Mitigation only Fix from $1,6002019-09-10 MEDIUM 6.1 CVE-2019-11464 Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Ty… Couchbase Server Mitigation only Fix from $1,6002019-09-10 MEDIUM 5.3 CVE-2019-11465 An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted userna… Couchbase Server after 5.5.3 Fix from $1,6002019-09-10 CRITICAL 9.8 CVE-2019-9039 In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extra… Sync Gateway No fix yet Fix from $2,3002019-06-26 HIGH 8.8 CVE-2018-15728 Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad… Couchbase Server No fix yet Fix from $1,9502018-08-24