CVE-2022-33173: High severity wut com-server highspeed 100baselx vulnerability
Published Jul 11, 2022
·Updated
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.
Affected Software
1 affected component
Couchbase Couchbase Server>=6.6.0<7.0.4
Event History
Jul 11, 2022
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-33173.
2
What is the severity of CVE-2022-33173?
The severity of CVE-2022-33173 is high with a CVSS score of 7.5.
3
What software versions are affected by CVE-2022-33173?
Couchbase Server versions from 6.6.0 to 7.0.4 are affected by CVE-2022-33173.
4
What is the issue with Analytics Remote Links in Couchbase Server?
The issue is an algorithm-downgrade problem where Analytics Remote Links may temporarily downgrade to non-TLS connection using SCRAM-SHA instead of TLS to determine the TLS port number.
5
How can I fix CVE-2022-33173?
To fix CVE-2022-33173, you should upgrade to Couchbase Server version 7.0.4 or later.