CVE-2023-50437: High severity wut com-server highspeed 100baselx vulnerability
Published Feb 28, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.
Affected Software
2 affected components
Couchbase Couchbase Server<7.2.4
Couchbase Couchbase Server>=2.0.0<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:42 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50437?
CVE-2023-50437 has a critical severity level due to the exposure of sensitive admin information.
2
How do I fix CVE-2023-50437?
To fix CVE-2023-50437, update Couchbase Server to version 7.2.4 or later.
3
What versions of Couchbase Server are affected by CVE-2023-50437?
CVE-2023-50437 affects Couchbase Server versions prior to 7.2.4.
4
What type of data is exposed in CVE-2023-50437?
CVE-2023-50437 exposes the otpCookie with full admin access on specific server group details.
5
Is there a workaround for CVE-2023-50437?
As of now, the recommended action for CVE-2023-50437 is to upgrade to a non-vulnerable version.