CVE-2021-37842: High severity wut com-server highspeed 100baselx vulnerability
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37842?
CVE-2021-37842 is a vulnerability in Couchbase Server 7.0.0 that allows sensitive information, such as Remote Cluster XDCR credentials, to be stored in cleartext in debug logs.
How does CVE-2021-37842 affect Couchbase Server?
CVE-2021-37842 affects Couchbase Server versions 7.0.0 and 7.0.1.
What is the severity of CVE-2021-37842?
The severity of CVE-2021-37842 is high, with a CVSS score of 7.5.
How can the vulnerability be exploited?
The vulnerability can be exploited by an attacker being able to access the debug logs of Couchbase Server 7.0.0 and 7.0.1.
Is there a fix for CVE-2021-37842?
Yes, a fix is available for CVE-2021-37842. It is recommended to upgrade to a version of Couchbase Server that is not affected by this vulnerability.