Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37034


An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.


Published

2024-07-26T22:15:03.853

Last Modified

2025-03-14T16:15:31.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-326
  • Type: Secondary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application couchbase couchbase_server < 7.2.5 Yes
Application couchbase couchbase_server 7.6.0 Yes

References