couchbase couchbase-server CVE-2021-42763 is a vulnerability in Couchbase Server
Published on November 2, 2021

Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.

NVD


Products Associated with CVE-2021-42763

Want to know whenever a new CVE is published for Couchbase Server? stack.watch will email you.

 

Exploit Probability

EPSS
0.20%
Percentile
42.14%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.