threat
engine
.sh
Back
·
··:··
Home
/
Product
/
couchbase server
Product
couchbase server
63 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-46619
>= 2.0.0 and < 7.2.7
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allo
7.6
HIGH
CVE-2024-56178
>= 7.6.0 and <= 7.6.3
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user i
6.5
MEDIUM
CVE-2024-25673
>= 2.0.0 and < 7.2.6
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
6.1
MEDIUM
CVE-2024-37034
>= 6.0.0 and < 7.2.5
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiate
5.9
MEDIUM
CVE-2023-43768
>= 6.6.0 and < 7.1.5
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached
7.5
HIGH
CVE-2024-23302
< 7.2.4
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
7.5
HIGH
CVE-2023-50437
>= 2.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverG
8.6
HIGH
CVE-2023-50436
>= 7.1.5 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log f
5.3
MEDIUM
CVE-2023-49932
>= 5.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
5.4
MEDIUM
CVE-2023-49931
>= 5.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
9.8
CRITICAL
CVE-2023-49930
>= 7.1.5 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
9.8
CRITICAL
CVE-2023-45874
>= 6.5.0 and < 7.2.4
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
4.3
MEDIUM
CVE-2023-43769
>= 6.0.0 and < 7.2.4
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Por
6.3
MEDIUM
CVE-2023-49338
>= 4.0.0 and < 7.2.4
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on
7.5
HIGH
CVE-2023-45873
< 7.2.3
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because
6.5
MEDIUM
CVE-2023-50782
all versions
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS se
7.5
HIGH
CVE-2024-0519
< 7.2.5
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2023-36667
>= 2.0.0 and < 7.1.5
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
7.5
HIGH
CVE-2023-45875
all versions
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 c
7.5
HIGH
CVE-2023-3079
< 7.1.5
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via
8.8
HIGH
CVE-2023-2033
< 7.1.5
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via
8.8
HIGH
CVE-2023-28470
>= 6.6.0 and < 7.1.4
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
5.3
MEDIUM
CVE-2023-25016
>= 2.0.0 and < 6.6.6
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
7.5
HIGH
CVE-2022-42951
>= 6.5.0 and < 6.6.6
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the sta
8.1
HIGH
CVE-2022-42950
>= 7.0.0 and < 7.0.5
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administr
4.9
MEDIUM
CVE-2022-32556
>= 3.0.0 and < 7.1.1
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
7.5
HIGH
CVE-2022-34826
all versions
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
5.9
MEDIUM
CVE-2022-33911
>= 6.5.0 and < 7.0.4
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analy
5.3
MEDIUM
CVE-2022-33173
>= 6.6.0 and < 7.0.4
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to
7.5
HIGH
CVE-2022-32561
>= 5.0.0 and < 6.6.5
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found
4.9
MEDIUM
CVE-2022-32559
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
9.1
CRITICAL
CVE-2022-32557
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
7.5
HIGH
CVE-2022-32565
>= 7.0.0 and < 7.1.0
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
7.5
HIGH
CVE-2022-32562
>= 7.0.0 and <= 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
8.8
HIGH
CVE-2022-32192
>= 5.0.0 and < 7.0.4
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
7.5
HIGH
CVE-2022-32564
< 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.
7.5
HIGH
CVE-2022-32560
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
7.5
HIGH
CVE-2022-32558
>= 6.6.0 and <= 6.6.3
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
7.5
HIGH
CVE-2022-32193
>= 6.6.0 and <= 6.6.3
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
6.5
MEDIUM
CVE-2021-33504
>= 2.0.0 and < 7.1.0
Couchbase Server before 7.1.0 has Incorrect Access Control.
4.9
MEDIUM
CVE-2021-42763
< 4.6.0
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster ma
7.5
HIGH
CVE-2021-37842
all versions
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leak
7.5
HIGH
CVE-2021-35945
>= 4.5.0 and <= 5.5.6
Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an att
7.5
HIGH
CVE-2021-35944
>= 6.5.0 and <= 6.5.2
Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an atta
7.5
HIGH
CVE-2021-35943
>= 6.5.0 and <= 6.5.2
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using
9.8
CRITICAL
CVE-2021-25643
>= 5.0.0 and < 6.5.2
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator pri
4.9
MEDIUM
CVE-2021-27924
>= 6.0.0 and < 6.6.2
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in th
5.9
MEDIUM
CVE-2021-31158
>= 6.5.0 and < 6.6.2
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking
6.5
MEDIUM
CVE-2021-27925
>= 6.5.0 and < 6.6.2
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a c
4.4
MEDIUM
CVE-2021-25644
>= 5.0.0 and <= 6.6.1
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can resul
7.5
HIGH
CVE-2021-25645
< 6.0.5
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal us
4.4
MEDIUM
CVE-2020-24719
>= 6.5.1 and < 6.6.0
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchangin
9.8
CRITICAL
CVE-2020-9042
all versions
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their b
8.8
HIGH
CVE-2020-9041
all versions
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search end
7.5
HIGH
CVE-2020-9039
>= 4.6.0 and <= 4.6.5
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions f
9.8
CRITICAL
CVE-2019-11497
all versions
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not
7.5
HIGH
CVE-2019-11496
<= 5.0.0
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access w
9.1
CRITICAL
CVE-2019-11495
all versions
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:n
9.8
CRITICAL
CVE-2019-11467
all versions
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries co
7.5
HIGH
CVE-2019-11466
all versions
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not req
5.3
MEDIUM
CVE-2019-11465
>= 5.5.0 and <= 5.5.3
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a
5.3
MEDIUM
CVE-2019-11464
all versions
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Optio
6.1
MEDIUM
CVE-2018-15728
all versions
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin