metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
References
Link | Resource |
---|---|
https://www.couchbase.com/alerts | Vendor Advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-11-02 05:15
Updated : 2021-11-08 06:53
NVD link : CVE-2021-37842
Mitre link : CVE-2021-37842
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
couchbase
- couchbase_server