CVE-2022-42950
Last modified
CVE-2022-42950 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | Couchbase Server | >= 7.0.0, < 7.0.5 |
| Couchbase | Couchbase Server | >= 7.1.0, < 7.1.2 |
References
- https://forums.couchbase.com/tags/securityIssue Tracking
- https://www.couchbase.com/alerts/Vendor Advisory
- https://forums.couchbase.com/tags/securityIssue Tracking
- https://www.couchbase.com/alerts/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-42950?
How severe is CVE-2022-42950?
How do I fix CVE-2022-42950?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-42945DWG TrueViewTM 2023 version has a DLL Search Order Hijacking…7.8
- CVE-2022-42946Parsing a maliciously crafted X_B and PRT file can force Aut…7.1
- CVE-2022-42947A maliciously crafted X_B file when parsed through Autodesk …7.8
- CVE-2022-42948Cobalt Strike 4.7.1 fails to properly escape HTML tags when …9.8
- CVE-2022-42949Silverstripe silverstripe/subsites through 2.6.0 has Insecur…7.5
- CVE-2022-4295The Show All Comments WordPress plugin before 7.0.1 does not…6.1
- CVE-2022-42951An issue was discovered in Couchbase Server 6.5.x and 6.6.x …8.1
- CVE-2022-42953Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM…7.5
- CVE-2022-42954Keyfactor EJBCA before 7.10.0 allows XSS.5.4
- CVE-2022-42955The PassWork extension 5.0.9 for Chrome and other browsers a…7.5
- CVE-2022-42956The PassWork extension 5.0.9 for Chrome and other browsers a…7.5
- CVE-2022-4296A vulnerability classified as problematic has been found in …5.5
Are you affected by CVE-2022-42950?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
