CVE-2023-36667

CVSS 3.1 Score 7.5 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity none
Availability none
Scope unchanged
Privileges Required none

Details

Published Nov 8, 2023
Updated: Nov 15, 2023
CWE ID 22

Summary

CVE-2023-36667 is a newly disclosed vulnerability affecting Couchbase Server versions 7.1.4 and 7.2.0 before the respective patches 7.1.5 and 7.2.1. This issue permits an attacker to traverse directories, possibly gaining unauthorized access to sensitive data. The vulnerability is due to an improper input validation in the server's file handling component. Exploitation of this vulnerability could result in serious data breaches or unintended system modifications. It is highly recommended that affected users install the respective security updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Couchbase Server

Affected Vendors

  • Couchbase