metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
References
Link | Resource |
---|---|
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
https://www.couchbase.com/alerts | Vendor Advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
https://www.couchbase.com/alerts | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.couchbase.com/server/current/release-notes/relnotes.html - Release Notes, Vendor Advisory | |
References | () https://www.couchbase.com/alerts - Vendor Advisory |
Information
Published : 2021-11-02 12:15
Updated : 2024-11-21 06:15
NVD link : CVE-2021-37842
Mitre link : CVE-2021-37842
CVE.ORG link : CVE-2021-37842
JSON object : View
Products Affected
couchbase
- couchbase_server
CWE
CWE-312
Cleartext Storage of Sensitive Information