A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
History

Tue, 13 May 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Couchbase
Couchbase couchbase Server
Microsoft
Microsoft windows
CPEs cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Couchbase
Couchbase couchbase Server
Microsoft
Microsoft windows

Thu, 01 May 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 18:00:00 +0000

Type Values Removed Values Added
Description A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-01T18:54:24.138Z

Reserved: 2025-04-26T00:00:00.000Z

Link: CVE-2025-46619

cve-icon Vulnrichment

Updated: 2025-05-01T18:54:17.113Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-30T18:15:48.220

Modified: 2025-05-13T20:26:39.127

Link: CVE-2025-46619

cve-icon Redhat

No data.