An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Couchbase_server | Couchbase | 6.0.0 (including) | 7.2.5 (excluding) |
Couchbase_server | Couchbase | 7.6.0 (including) | 7.6.0 (including) |