CVE-2023-36667

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 8, 2023
Updated: Nov 15, 2023
CWE ID 22

Summary

CVE-2023-36667 is a newly disclosed vulnerability affecting Couchbase Server versions 7.1.4 and 7.2.0 before the respective patches 7.1.5 and 7.2.1. This issue permits an attacker to traverse directories, possibly gaining unauthorized access to sensitive data. The vulnerability is due to an improper input validation in the server's file handling component. Exploitation of this vulnerability could result in serious data breaches or unintended system modifications. It is highly recommended that affected users install the respective security updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Couchbase Server

Affected Vendors

  • Couchbase