CVE-2024-23302: Infoleak
Published Feb 28, 2024
·Updated
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Affected Software
1 affected component
Couchbase Couchbase Server<7.2.4
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23302?
CVE-2024-23302 has a high severity level due to the risk of private key leakage.
2
How do I fix CVE-2024-23302?
To fix CVE-2024-23302, upgrade Couchbase Server to version 7.2.4 or later.
3
What information is leaked in CVE-2024-23302?
CVE-2024-23302 exposes private keys through the goxdcr.log file.
4
Which versions of Couchbase Server are affected by CVE-2024-23302?
CVE-2024-23302 affects all versions of Couchbase Server before 7.2.4.
5
Is there a workaround for CVE-2024-23302?
There is no known workaround for CVE-2024-23302; upgrading is the recommended solution.