CVE-2021-25644: High severity wut com-server highspeed 100baselx vulnerability
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25644.
What is the severity of CVE-2021-25644?
The severity of CVE-2021-25644 is high with a score of 7.5.
Which versions of Couchbase Server are affected by CVE-2021-25644?
Couchbase Server 5.x, 6.x (up to 6.6.1), and 7.0.0 Beta are affected by CVE-2021-25644.
What is the impact of CVE-2021-25644?
Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
How can I fix CVE-2021-25644?
Upgrade to a version of Couchbase Server that is not affected by CVE-2021-25644 and follow the recommendations provided by Couchbase.