ZeroHour

CVE-2021-35943

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.

Vendors
couchbase
Products
couchbase server
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.