An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://forums.couchbase.com/tags/security | vendor advisory |
https://docs.couchbase.com/server/current/release-notes/relnotes.html | release notes |
https://www.couchbase.com/alerts/ | vendor advisory |