First published: Fri Jul 26 2024(Updated: )
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Couchbase Server | >=6.0.0<7.2.5 | |
Couchbase Server | =7.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37034 is classified as a medium severity vulnerability.
To fix CVE-2024-37034, upgrade Couchbase Server to version 7.2.5 or 7.6.1 or later.
CVE-2024-37034 may lead to unauthorized access to credentials when using the Key-Value service with Half-Secure remote link encryption.
Couchbase Server versions prior to 7.2.5 and 7.6.0 are affected by CVE-2024-37034.
CVE-2024-37034 affects configurations that do not use SCRAM-SHA for credential negotiation in Half-Secure remote link encryption.