Описание
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.
Ссылки
- ProductVendor Advisory
- Vendor Advisory
- ProductVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.5.0 (включая) до 6.6.2 (исключая)
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00238
Низкий
4.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-362
Связанные уязвимости
CVSS3: 4.4
github
больше 3 лет назад
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.
EPSS
Процентиль: 47%
0.00238
Низкий
4.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-362