CVE-2024-37034: Weak Encryption
Published Jul 26, 2024
·Updated
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
Affected Software
2 affected components
Couchbase Couchbase Server>=6.0.0<7.2.5
Couchbase Couchbase Server=7.6.0
Event History
Jul 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-37034?
CVE-2024-37034 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-37034?
To fix CVE-2024-37034, upgrade Couchbase Server to version 7.2.5 or 7.6.1 or later.
3
What impact does CVE-2024-37034 have on Couchbase Server?
CVE-2024-37034 may lead to unauthorized access to credentials when using the Key-Value service with Half-Secure remote link encryption.
4
Is my Couchbase Server affected by CVE-2024-37034?
Couchbase Server versions prior to 7.2.5 and 7.6.0 are affected by CVE-2024-37034.
5
What configurations are vulnerable in CVE-2024-37034?
CVE-2024-37034 affects configurations that do not use SCRAM-SHA for credential negotiation in Half-Secure remote link encryption.