An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
References
Link | Resource |
---|---|
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
https://forums.couchbase.com/tags/security | Vendor Advisory |
https://www.couchbase.com/alerts | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2022-07-12 14:15
Updated : 2022-07-18 19:04
NVD link : CVE-2022-33911
Mitre link : CVE-2022-33911
CVE.ORG link : CVE-2022-33911
JSON object : View
Products Affected
couchbase
- couchbase_server
CWE
CWE-532
Insertion of Sensitive Information into Log File