First published: Tue Jun 14 2022(Updated: )
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=5.0.0<6.6.5 | |
Couchbase Couchbase Server | >=7.0.0<7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Couchbase Server is CVE-2022-32561.
CVE-2022-32561 has a severity rating of medium.
The affected software versions for CVE-2022-32561 are Couchbase Server versions between 5.0.0 and 6.6.5, and versions between 7.0.0 and 7.0.4.
CVE-2022-32561 could allow unauthorized remote access to diagnostic endpoints in Couchbase Server.
To mitigate the vulnerability in Couchbase Server, it is recommended to update to version 6.6.5 or 7.0.4, depending on the affected software version.