CVE-2022-42951

CVSS V2 None CVSS V3 None
Description
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.
Overview
  • CVE ID
  • CVE-2022-42951
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-06T21:15:09
  • Last Modified Date
  • 2023-02-15T14:02:07
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:* 1 OR 6.5.0 6.6.6
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:* 1 OR 7.0.0 7.0.5
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:* 1 OR 7.1.0 7.1.2
History
Created Old Value New Value Data Type Notes
2023-04-17 07:18:28 Added to TrackCVE
2023-04-17 07:18:30 Weakness Enumeration new