5
CVSSv2

CVE-2021-42763

Published: 02/11/2021 Updated: 08/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Couchbase Server prior to 6.6.3 and 7.x prior to 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

couchbase couchbase server

couchbase couchbase server 7.0.0

couchbase couchbase server 7.0.1