CVE-2021-27924
19.05.2021, 20:15
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.Enginsight
Vendor | Product | Version |
---|---|---|
couchbase | couchbase_server | 6.0.0 ≤ 𝑥 < 6.6.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration