First published: Wed Sep 29 2021(Updated: )
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=6.5.0<=6.5.2 | |
Couchbase Couchbase Server | >=6.6.0<6.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35943 is a vulnerability in Couchbase Server 6.5.x and 6.6.x through 6.6.2 that allows externally managed users to use an empty password.
The severity of CVE-2021-35943 is critical with a CVSS score of 9.8.
CVE-2021-35943 allows externally managed users to bypass password requirements in Couchbase Server 6.5.x and 6.6.x through 6.6.2.
To fix CVE-2021-35943, users should upgrade their Couchbase Server to a version that includes the patch.
More information about CVE-2021-35943 can be found in the release notes of Couchbase Server and on the Couchbase website.