Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
References
Link | Resource |
---|---|
https://docs.couchbase.com/server/current/release-notes/relnotes.html | Release Notes |
https://forums.couchbase.com/tags/security | Issue Tracking |
https://www.couchbase.com/alerts/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-09-19 19:15
Updated : 2025-03-19 21:15
NVD link : CVE-2024-25673
Mitre link : CVE-2024-25673
CVE.ORG link : CVE-2024-25673
JSON object : View
Products Affected
couchbase
- couchbase_server
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')