An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
References
Link | Resource |
---|---|
https://www.couchbase.com/alerts | Vendor Advisory |
https://forums.couchbase.com/tags/security | Vendor Advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes Vendor Advisory |
Configurations
Information
Published : 2022-07-12 07:15
Updated : 2022-07-18 12:04
NVD link : CVE-2022-33911
Mitre link : CVE-2022-33911
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
couchbase
- couchbase_server