First published: Mon Feb 06 2023(Updated: )
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=7.0.0<7.0.5 | |
Couchbase Couchbase Server | >=7.1.0<7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-42950.
The severity of CVE-2022-42950 is medium with a CVSS score of 4.9.
Couchbase Server versions 7.x before 7.0.5 and 7.1.x before 7.1.2 are affected by CVE-2022-42950.
CVE-2022-42950 can be used for denial of service, as it can exhaust memory resources and cause the process to be killed.
To fix CVE-2022-42950, update Couchbase Server to version 7.0.5 or 7.1.2 or later.