Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px2c-r924-mwcc

Опубликовано: 18 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

Пакеты

Наименование

CouchbaseNetClient

nuget
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 10%
0.00035
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-297

Связанные уязвимости

CVSS3: 4.9
nvd
8 месяцев назад

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

CVSS3: 4.9
debian
8 месяцев назад

The Couchbase .NET SDK (client library) before 3.7.1 does not properly ...

EPSS

Процентиль: 10%
0.00035
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-297