Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Couchbase Server HIGH 7.5
CVE-2023-45875

An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

Mitigation only
Fix from $1,950 2023-11-08
Couchbase Server MEDIUM 5.9
CVE-2022-34826

In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.

Mitigation only
Fix from $1,600 2022-07-15
Couchbase Server HIGH 7.5
CVE-2021-37842

metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. C…

Mitigation only
Fix from $1,950 2021-11-02
Couchbase Server HIGH 8.8
CVE-2020-9042

In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the…

Mitigation only
Fix from $1,950 2020-06-08
Couchbase Server CRITICAL 9.8
CVE-2019-11495

In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR…

Mitigation only
Fix from $2,300 2019-09-10
Couchbase Server HIGH 7.5
CVE-2019-11467

In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries contain certain chara…

Mitigation only
Fix from $1,950 2019-09-10
Couchbase Server HIGH 7.5
CVE-2019-11497

In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the…

Mitigation only
Fix from $1,950 2019-09-10
Couchbase Server MEDIUM 5.3
CVE-2019-11466

In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on…

Mitigation only
Fix from $1,600 2019-09-10
Couchbase Server MEDIUM 6.1
CVE-2019-11464

Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Ty…

Mitigation only
Fix from $1,600 2019-09-10
Sync Gateway CRITICAL 9.8
CVE-2019-9039

In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extra…

No fix yet
Fix from $2,300 2019-06-26
Couchbase Server HIGH 8.8
CVE-2018-15728

Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Ad…

No fix yet
Fix from $1,950 2018-08-24