Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27925

Опубликовано: 19 мая 2021
Источник: nvd
CVSS3: 4.4
CVSS2: 3.5
EPSS Низкий

Описание

An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
Версия от 6.5.0 (включая) до 6.6.2 (исключая)

EPSS

Процентиль: 47%
0.00238
Низкий

4.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 4.4
github
больше 3 лет назад

An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.

EPSS

Процентиль: 47%
0.00238
Низкий

4.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-362