First published: Mon Jul 11 2022(Updated: )
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Server | >=6.6.0<7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-33173.
The severity of CVE-2022-33173 is high with a CVSS score of 7.5.
Couchbase Server versions from 6.6.0 to 7.0.4 are affected by CVE-2022-33173.
The issue is an algorithm-downgrade problem where Analytics Remote Links may temporarily downgrade to non-TLS connection using SCRAM-SHA instead of TLS to determine the TLS port number.
To fix CVE-2022-33173, you should upgrade to Couchbase Server version 7.0.4 or later.