An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://forums.couchbase.com/tags/security | vendor advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | release notes |
https://www.couchbase.com/alerts/ | vendor advisory |