CVE-2021-25644

HIGH

Couchbase Server 5.x-6.6.1 and 7.0.0 Beta - Cleartext Storage of Sensitive Information in Log Files

Title source: llm
STIX 2.1

Description

An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://www.couchbase.com/downloads

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (2)
couchbase/couchbase_server 7.0.0 beta
couchbase/couchbase_server 5.0.0 - 6.6.1
Published May 19, 2021
Tracked Since Feb 18, 2026