CVE-2022-33911: Medium severity wut com-server highspeed 100baselx vulnerability
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-33911?
CVE-2022-33911 is a vulnerability discovered in Couchbase Server 7.x before 7.0.4 where field names are not redacted in logged validation messages for Analytics Service, allowing unauthorized actors to obtain sensitive information.
What is the severity of CVE-2022-33911?
The severity of CVE-2022-33911 is medium, with a CVSSv3 score of 5.3.
How can an unauthorized actor exploit CVE-2022-33911?
An unauthorized actor can exploit CVE-2022-33911 by accessing the logged validation messages for Analytics Service and obtaining sensitive information.
Which version of Couchbase Server is affected by CVE-2022-33911?
Couchbase Server versions between 6.5.0 and 7.0.4 are affected by CVE-2022-33911.
How can I fix CVE-2022-33911?
To fix CVE-2022-33911, it is recommended to upgrade to Couchbase Server version 7.0.4 or later.