CVE-2024-56178: Medium severity couchbase vulnerability
Published Jan 27, 2025
·Updated
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the securityadminlocal role can create a new user in a group that has the admin role.
Affected Software
2 affected components
Couchbase Server>=7.6.x<=7.6.3
Couchbase Couchbase Server>=7.6.0<=7.6.3
Event History
Jan 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56178?
CVE-2024-56178 is classified as a high severity vulnerability.
2
How do I fix CVE-2024-56178?
To address CVE-2024-56178, it is recommended to upgrade your Couchbase Server to a version higher than 7.6.3.
3
Who is affected by CVE-2024-56178?
CVE-2024-56178 affects users of Couchbase Server versions 7.6.x through 7.6.3 with the security_admin_local role.
4
What can an attacker do with CVE-2024-56178?
An attacker with the security_admin_local role can create new users in an admin role group, potentially granting them elevated privileges.
5
Is there a workaround for CVE-2024-56178?
Currently, there are no documented workarounds for CVE-2024-56178; the best course of action is to upgrade.