Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-42951

Опубликовано: 06 фев. 2023
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
Версия от 6.5.0 (включая) до 6.6.6 (исключая)
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.5 (исключая)
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
Версия от 7.1.0 (включая) до 7.1.2 (исключая)

EPSS

Процентиль: 49%
0.00261
Низкий

8.1 High

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 8.1
github
около 3 лет назад

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.

EPSS

Процентиль: 49%
0.00261
Низкий

8.1 High

CVSS3

Дефекты

CWE-287
CWE-287