CVE-2025-46619

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

13 May 2025, 20:26

Type Values Removed Values Added
CPE cpe:2.3:a:couchbase:couchbase_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
First Time Couchbase couchbase Server
Couchbase
Microsoft windows
Microsoft
References () https://docs.couchbase.com/server/current/release-notes/relnotes.html - () https://docs.couchbase.com/server/current/release-notes/relnotes.html - Release Notes
References () https://forums.couchbase.com/tags/security - () https://forums.couchbase.com/tags/security - Vendor Advisory
References () https://www.couchbase.com/alerts/ - () https://www.couchbase.com/alerts/ - Vendor Advisory

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema de seguridad en Couchbase Server antes de la versión 7.6.4, corregido en las versiones 7.6.4 y 7.2.7 para Windows, que podría permitir el acceso no autorizado a archivos confidenciales. Según el nivel de privilegios, esta vulnerabilidad puede otorgar acceso a archivos como /etc/passwd o /etc/shadow.

01 May 2025, 19:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

30 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 18:15

Updated : 2025-05-13 20:26


NVD link : CVE-2025-46619

Mitre link : CVE-2025-46619

CVE.ORG link : CVE-2025-46619


JSON object : View

Products Affected

microsoft

  • windows

couchbase

  • couchbase_server
CWE
CWE-284

Improper Access Control