An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.couchbase.com/alerts/ |
|
History
Fri, 14 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Couchbase
Couchbase couchbase Server |
|
| Weaknesses | CWE-326 | |
| CPEs | cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:* cpe:2.3:a:couchbase:couchbase_server:7.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Couchbase
Couchbase couchbase Server |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-26T00:00:00.000Z
Updated: 2025-03-14T16:03:26.661Z
Reserved: 2024-05-31T00:00:00.000Z
Link: CVE-2024-37034
Updated: 2024-08-02T03:43:50.983Z
Status : Modified
Published: 2024-07-26T22:15:03.853
Modified: 2025-03-14T16:15:31.970
Link: CVE-2024-37034
No data.