Couchbase Server before 6.6.3 and... CVE-2021-42763

5.0 AV AC AU C I A
发布: 2021-11-02
修订: 2024-11-21

Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息