Vulnerability Description
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | Couchbase Server | >= 6.5.0, < 6.6.2 |
Related Weaknesses (CWE)
References
- https://docs.couchbase.com/server/current/release-notes/relnotes.htmlRelease NotesVendor Advisory
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
- https://docs.couchbase.com/server/current/release-notes/relnotes.htmlRelease NotesVendor Advisory
- https://www.couchbase.com/resources/security#SecurityAlertsVendor Advisory
FAQ
What is CVE-2021-31158?
CVE-2021-31158 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what...
How severe is CVE-2021-31158?
CVE-2021-31158 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31158?
Check the references section above for vendor advisories and patch information. Affected products include: Couchbase Couchbase Server.