PT-2022-21904 · Couchbase · Couchbase Server

Published

2022-07-11

·

Updated

2022-07-18

·

CVE-2022-33911

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Couchbase Server versions prior to 7.0.4
Description An issue in Couchbase Server allows unauthorized actors to potentially obtain sensitive information due to field names not being redacted in logged validation messages for the Analytics Service.
Recommendations For versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33911

Affected Products

Couchbase Server