CVE-2021-42763: High severity wut com-server highspeed 100baselx vulnerability
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-42763.
What is the severity level of CVE-2021-42763?
The severity level of CVE-2021-42763 is high (7.5).
Which versions of Couchbase Server are affected by CVE-2021-42763?
Couchbase Server versions before 6.6.3 and 7.x before 7.0.2 are affected by CVE-2021-42763.
How does CVE-2021-42763 exploit work?
The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service, exposing sensitive information in cleartext.
How can I fix CVE-2021-42763?
To fix CVE-2021-42763, update Couchbase Server to version 6.6.3 or 7.0.2 or later.