CVE-2021-35943

EUVD-2021-22578
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
couchbasecouchbase_server
6.5.0 ≤
𝑥
≤ 6.5.2
couchbasecouchbase_server
6.6.0 ≤
𝑥
< 6.6.3
𝑥
= Vulnerable software versions