An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
2024-07-26T22:15:03.853
2025-03-14T16:15:31.970
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | couchbase | couchbase_server | < 7.2.5 | Yes |
Application | couchbase | couchbase_server | 7.6.0 | Yes |