First published: Tue Sep 10 2019(Updated: )
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed (in 5.5.4 and 6.0.1) so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=5.5.0<=5.5.3 | |
Couchbase Couchbase Server | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11465 is a vulnerability discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0 that exposes non-redacted usernames through the Memcached "connections" stat block command.
CVE-2019-11465 allows the usernames of all users currently logged into the system to be exposed in the system information submitted to Couchbase as part of a bug report.
The severity of CVE-2019-11465 is medium, with a severity score of 5.3.
To fix CVE-2019-11465, it is recommended to upgrade Couchbase Server to a version that addresses the vulnerability.
More information about CVE-2019-11465 can be found at the following link: https://www.couchbase.com/resources/security#SecurityAlerts