SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11465

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0.

MEDIUM 5.3EPSS 1.17%

Does this matter?

Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed (in 5.5.4 and 6.0.1) so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
couchbase/couchbase server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.