First published: Mon Feb 06 2023(Updated: )
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Couchbase Server | >=6.5.0<6.6.6 | |
Couchbase Couchbase Server | >=7.0.0<7.0.5 | |
Couchbase Couchbase Server | >=7.1.0<7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-42951 is high, with a severity value of 8.1.
Couchbase Server versions 6.5.x, 6.6.x, 7.x, and 7.1.x are affected by CVE-2022-42951.
During the start-up of a Couchbase Server node, there is a small window of time where an attacker can connect to the cluster before the cluster management authentication has started.
Update to Couchbase Server version 6.6.6, 7.0.5, or 7.1.2 or later to fix CVE-2022-42951.
The references for CVE-2022-42951 are: [documentation](https://docs.couchbase.com/server/current/release-notes/relnotes.html), [forums](https://forums.couchbase.com/tags/security), and [alerts](https://www.couchbase.com/alerts/).