An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.couchbase.com/alerts/ |
History
Thu, 19 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Couchbase
Couchbase couchbase Server |
|
Weaknesses | CWE-326 | |
CPEs | cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:* cpe:2.3:a:couchbase:couchbase_server:7.6.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Couchbase
Couchbase couchbase Server |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-26T00:00:00
Updated: 2024-08-02T03:43:50.983Z
Reserved: 2024-05-31T00:00:00
Link: CVE-2024-37034
Vulnrichment
Updated: 2024-08-02T03:43:50.983Z
NVD
Status : Modified
Published: 2024-07-26T22:15:03.853
Modified: 2024-11-21T09:23:05.303
Link: CVE-2024-37034
Redhat
No data.