CVE-2024-25673: Medium severity couchbase server vulnerability
Published Sep 19, 2024
·Updated
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
Affected Software
2 affected components
Couchbase Couchbase Server>=2.0.0<7.2.6
Couchbase Couchbase Server>=7.6.0<7.6.2
Event History
Sep 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-25673?
CVE-2024-25673 is classified as a high severity vulnerability due to HTTP Host header injection risks.
2
What versions of Couchbase Server are affected by CVE-2024-25673?
CVE-2024-25673 affects Couchbase Server versions before 7.6.2, 7.2.6, and all earlier versions.
3
How do I fix CVE-2024-25673?
To fix CVE-2024-25673, upgrade to Couchbase Server version 7.6.2 or 7.2.6 or later.
4
What type of vulnerability is CVE-2024-25673?
CVE-2024-25673 is an HTTP Host header injection vulnerability.
5
What impact can CVE-2024-25673 have on my system?
CVE-2024-25673 can allow attackers to manipulate HTTP requests, potentially leading to further exploitation.