CVE-2024-37034

CWE-3263 documents3 sources
Severity
5.9MEDIUM
EPSS
0.2%
top 59.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26
Latest updateJul 27

Description

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDcouchbase/couchbase_server6.0.07.2.5+1

🔴Vulnerability Details

2
GHSA
GHSA-mpp7-xq5h-6fjh: An issue was discovered in Couchbase Server before 72024-07-27
CVEList
CVE-2024-37034: An issue was discovered in Couchbase Server before 72024-07-26