An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
References
Link | Resource |
---|---|
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
https://forums.couchbase.com/tags/security | Vendor Advisory |
https://www.couchbase.com/alerts | Vendor Advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
https://forums.couchbase.com/tags/security | Vendor Advisory |
https://www.couchbase.com/alerts | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.couchbase.com/server/current/release-notes/relnotes.html - Release Notes, Vendor Advisory | |
References | () https://forums.couchbase.com/tags/security - Vendor Advisory | |
References | () https://www.couchbase.com/alerts - Vendor Advisory |
Information
Published : 2022-07-12 14:15
Updated : 2024-11-21 07:08
NVD link : CVE-2022-33911
Mitre link : CVE-2022-33911
CVE.ORG link : CVE-2022-33911
JSON object : View
Products Affected
couchbase
- couchbase_server
CWE
CWE-532
Insertion of Sensitive Information into Log File