CVE-2022-42950Uncontrolled Resource Consumption in Server

Severity
4.9MEDIUMNVD
EPSS
1.1%
top 21.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 6

Description

An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages1 packages

NVDcouchbase/couchbase_server7.0.07.0.5+1

🔴Vulnerability Details

2
CVEList
CVE-2022-42950: An issue was discovered in Couchbase Server 72023-02-06
GHSA
GHSA-xrvm-qcmp-42vc: An issue was discovered in Couchbase Server 72023-02-06
CVE-2022-42950 — Uncontrolled Resource Consumption | cvebase