CVE-2021-27925: Race Condition
An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @nsserver, to have its credentials leaked in cleartext in the nsserver.info.log file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27925.
What is the severity of CVE-2021-27925?
The severity of CVE-2021-27925 is medium, with a severity value of 4.4.
Which versions of Couchbase Server are affected by CVE-2021-27925?
Couchbase Server versions 6.5.x and 6.6.x through 6.6.1 are affected by CVE-2021-27925.
How does CVE-2021-27925 impact Couchbase Server?
CVE-2021-27925 can cause a crash condition in Couchbase Server when using the View Engine and Auditing is enabled, potentially leaking the credentials of the internal user @ns_server in clear text.
How can I fix CVE-2021-27925?
To fix CVE-2021-27925, it is recommended to upgrade to Couchbase Server version 6.6.2 or later.