CVE-2023-2033
- EPSS 13.9%
- Veröffentlicht 14.04.2023 19:15:09
- Zuletzt bearbeitet 19.02.2025 19:44:57
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-28470
- EPSS 0.26%
- Veröffentlicht 23.03.2023 01:15:12
- Zuletzt bearbeitet 24.02.2025 16:15:11
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
CVE-2023-25016
- EPSS 0.13%
- Veröffentlicht 06.02.2023 21:15:09
- Zuletzt bearbeitet 25.03.2025 19:15:41
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
CVE-2022-42951
- EPSS 0.25%
- Veröffentlicht 06.02.2023 21:15:09
- Zuletzt bearbeitet 26.03.2025 15:15:40
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has star...
CVE-2022-42950
- EPSS 0.24%
- Veröffentlicht 06.02.2023 21:15:09
- Zuletzt bearbeitet 26.03.2025 15:15:39
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, whic...
CVE-2022-32556
- EPSS 0.51%
- Veröffentlicht 21.07.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 07:06:37
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
CVE-2022-34826
- EPSS 0.4%
- Veröffentlicht 15.07.2022 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:10:15
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
CVE-2022-33911
- EPSS 0.49%
- Veröffentlicht 12.07.2022 14:15:18
- Zuletzt bearbeitet 21.11.2024 07:08:35
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
CVE-2022-33173
- EPSS 0.51%
- Veröffentlicht 12.07.2022 14:15:16
- Zuletzt bearbeitet 21.11.2024 07:07:39
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.
CVE-2022-32557
- EPSS 0.39%
- Veröffentlicht 14.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:06:37
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.