CVE-2023-50436: Medium severity wut com-server highspeed 100baselx vulnerability
Published Feb 28, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.4. nsserver admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.
Affected Software
2 affected components
Couchbase Couchbase Server>=7.1.5<7.2.4
Couchbase Couchbase Server>=7.1.5<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:42 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50436?
CVE-2023-50436 has been classified with moderate severity due to the potential exposure of administrative credentials.
2
How do I fix CVE-2023-50436?
To fix CVE-2023-50436, upgrade to Couchbase Server version 7.2.4 or later.
3
What versions are affected by CVE-2023-50436?
CVE-2023-50436 affects Couchbase Server versions from 7.1.5 up to, but not including, 7.2.4.
4
What kind of information is leaked in CVE-2023-50436?
CVE-2023-50436 leads to the leakage of ns_server admin credentials in encoded form within the diag.log file.
5
Is CVE-2023-50436 a serious security threat?
While not critical, CVE-2023-50436 poses a security risk as it can lead to unauthorized access if the encoded credentials are compromised.