CVE-2021-37842
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
metakv en Couchbase Server versión 7.0.0, usa texto sin Cifrar para el almacenamiento de información confidencial. Las credenciales de cluster remoto XDCR pueden filtrarse en los registros de depuración. Se ha añadido la purga de claves de configuración en Couchbase Server versión 7.0.0. Este problema se produce cuando una clave de configuración, que se está registrando, presenta una marca de tiempo de purga de tumbas adjunta
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-02 CVE Reserved
- 2021-11-02 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-312: Cleartext Storage of Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.couchbase.com/server/current/release-notes/relnotes.html | 2021-11-08 | |
https://www.couchbase.com/alerts | 2021-11-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Couchbase Search vendor "Couchbase" | Couchbase Server Search vendor "Couchbase" for product "Couchbase Server" | 7.0.0 Search vendor "Couchbase" for product "Couchbase Server" and version "7.0.0" | - |
Affected
| ||||||
Couchbase Search vendor "Couchbase" | Couchbase Server Search vendor "Couchbase" for product "Couchbase Server" | 7.0.1 Search vendor "Couchbase" for product "Couchbase Server" and version "7.0.1" | - |
Affected
|