CVE-2022-33911

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:08

Type Values Removed Values Added
References () https://docs.couchbase.com/server/current/release-notes/relnotes.html - Release Notes, Vendor Advisory () https://docs.couchbase.com/server/current/release-notes/relnotes.html - Release Notes, Vendor Advisory
References () https://forums.couchbase.com/tags/security - Vendor Advisory () https://forums.couchbase.com/tags/security - Vendor Advisory
References () https://www.couchbase.com/alerts - Vendor Advisory () https://www.couchbase.com/alerts - Vendor Advisory

Information

Published : 2022-07-12 14:15

Updated : 2024-11-21 07:08


NVD link : CVE-2022-33911

Mitre link : CVE-2022-33911

CVE.ORG link : CVE-2022-33911


JSON object : View

Products Affected

couchbase

  • couchbase_server
CWE
CWE-532

Insertion of Sensitive Information into Log File