Home/Product/couchbase server
Product

couchbase server

63 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-46619
>= 2.0.0 and < 7.2.7
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allo
7.6HIGH
CVE-2024-56178
>= 7.6.0 and <= 7.6.3
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user i
6.5MEDIUM
CVE-2024-25673
>= 2.0.0 and < 7.2.6
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
6.1MEDIUM
CVE-2024-37034
>= 6.0.0 and < 7.2.5
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiate
5.9MEDIUM
CVE-2023-43768
>= 6.6.0 and < 7.1.5
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached
7.5HIGH
CVE-2024-23302
< 7.2.4
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
7.5HIGH
CVE-2023-50437
>= 2.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverG
8.6HIGH
CVE-2023-50436
>= 7.1.5 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log f
5.3MEDIUM
CVE-2023-49932
>= 5.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
5.4MEDIUM
CVE-2023-49931
>= 5.0.0 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
9.8CRITICAL
CVE-2023-49930
>= 7.1.5 and < 7.2.4
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
9.8CRITICAL
CVE-2023-45874
>= 6.5.0 and < 7.2.4
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
4.3MEDIUM
CVE-2023-43769
>= 6.0.0 and < 7.2.4
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Por
6.3MEDIUM
CVE-2023-49338
>= 4.0.0 and < 7.2.4
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on
7.5HIGH
CVE-2023-45873
< 7.2.3
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because
6.5MEDIUM
CVE-2023-50782
all versions
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS se
7.5HIGH
CVE-2024-0519
< 7.2.5
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2023-36667
>= 2.0.0 and < 7.1.5
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
7.5HIGH
CVE-2023-45875
all versions
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 c
7.5HIGH
CVE-2023-3079
< 7.1.5
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via
8.8HIGH
CVE-2023-2033
< 7.1.5
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via
8.8HIGH
CVE-2023-28470
>= 6.6.0 and < 7.1.4
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
5.3MEDIUM
CVE-2023-25016
>= 2.0.0 and < 6.6.6
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
7.5HIGH
CVE-2022-42951
>= 6.5.0 and < 6.6.6
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the sta
8.1HIGH
CVE-2022-42950
>= 7.0.0 and < 7.0.5
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administr
4.9MEDIUM
CVE-2022-32556
>= 3.0.0 and < 7.1.1
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
7.5HIGH
CVE-2022-34826
all versions
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
5.9MEDIUM
CVE-2022-33911
>= 6.5.0 and < 7.0.4
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analy
5.3MEDIUM
CVE-2022-33173
>= 6.6.0 and < 7.0.4
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to
7.5HIGH
CVE-2022-32561
>= 5.0.0 and < 6.6.5
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found
4.9MEDIUM
CVE-2022-32559
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
9.1CRITICAL
CVE-2022-32557
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
7.5HIGH
CVE-2022-32565
>= 7.0.0 and < 7.1.0
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
7.5HIGH
CVE-2022-32562
>= 7.0.0 and <= 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
8.8HIGH
CVE-2022-32192
>= 5.0.0 and < 7.0.4
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
7.5HIGH
CVE-2022-32564
< 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.
7.5HIGH
CVE-2022-32560
>= 4.0.0 and < 7.0.4
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
7.5HIGH
CVE-2022-32558
>= 6.6.0 and <= 6.6.3
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
7.5HIGH
CVE-2022-32193
>= 6.6.0 and <= 6.6.3
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
6.5MEDIUM
CVE-2021-33504
>= 2.0.0 and < 7.1.0
Couchbase Server before 7.1.0 has Incorrect Access Control.
4.9MEDIUM
CVE-2021-42763
< 4.6.0
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster ma
7.5HIGH
CVE-2021-37842
all versions
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leak
7.5HIGH
CVE-2021-35945
>= 4.5.0 and <= 5.5.6
Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an att
7.5HIGH
CVE-2021-35944
>= 6.5.0 and <= 6.5.2
Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an atta
7.5HIGH
CVE-2021-35943
>= 6.5.0 and <= 6.5.2
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using
9.8CRITICAL
CVE-2021-25643
>= 5.0.0 and < 6.5.2
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator pri
4.9MEDIUM
CVE-2021-27924
>= 6.0.0 and < 6.6.2
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in th
5.9MEDIUM
CVE-2021-31158
>= 6.5.0 and < 6.6.2
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking
6.5MEDIUM
CVE-2021-27925
>= 6.5.0 and < 6.6.2
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a c
4.4MEDIUM
CVE-2021-25644
>= 5.0.0 and <= 6.6.1
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can resul
7.5HIGH
CVE-2021-25645
< 6.0.5
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal us
4.4MEDIUM
CVE-2020-24719
>= 6.5.1 and < 6.6.0
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchangin
9.8CRITICAL
CVE-2020-9042
all versions
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their b
8.8HIGH
CVE-2020-9041
all versions
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search end
7.5HIGH
CVE-2020-9039
>= 4.6.0 and <= 4.6.5
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions f
9.8CRITICAL
CVE-2019-11497
all versions
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not
7.5HIGH
CVE-2019-11496
<= 5.0.0
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access w
9.1CRITICAL
CVE-2019-11495
all versions
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:n
9.8CRITICAL
CVE-2019-11467
all versions
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries co
7.5HIGH
CVE-2019-11466
all versions
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not req
5.3MEDIUM
CVE-2019-11465
>= 5.5.0 and <= 5.5.3
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a
5.3MEDIUM
CVE-2019-11464
all versions
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Optio
6.1MEDIUM
CVE-2018-15728
all versions
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin