Описание
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
Ссылки
- Release NotesVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.5.0 (включая) до 7.0.4 (исключая)
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00486
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
EPSS
Процентиль: 65%
0.00486
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532