Couchbase Sync Gateway
cpe:2.3:a:couchbase:sync_gateway:*:*:*:*:*:*:*
- >= 3.2.0, <= 3.2.5
A credential disclosure vulnerability has been identified in Couchbase Sync Gateway versions prior to 3.2.6. This issue arises from the unintentional exposure of cleartext passwords in the log files sgcollect_info_options.log and sync_gateway.log. The vulnerability occurs during the log collection process, where the credentials used to initiate the collection are not properly redacted, leading to a potential leakage of sensitive information.
The vulnerability could allow unauthorized individuals to access cleartext passwords, which could be used to gain administrative privileges on the Couchbase Server.
To reproduce this vulnerability, initiate a log collection process in an affected version of Couchbase Sync Gateway. Once the collection is complete, check the sgcollect_info_options.log and sync_gateway.log files for unredacted cleartext passwords.
Users can upgrade to Couchbase Sync Gateway version 3.2.6 or later to address this vulnerability. Additionally, it is recommended to rotate any credentials that were used to initiate log collection during the period when the vulnerability was present.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.