CVE-2025-52490: High severity Couchbase Sync Gateway vulnerability
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollectinfooptions.log and syncgateway.log, there are cleartext passwords in redacted and unredacted output.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52490?
CVE-2025-52490 has a severity rating that highlights significant security risks due to cleartext passwords being exposed in logs.
How do I fix CVE-2025-52490?
To fix CVE-2025-52490, upgrade to Couchbase Sync Gateway version 3.2.6 or later to mitigate the logging of cleartext passwords.
What specifically is affected by CVE-2025-52490?
CVE-2025-52490 affects Couchbase Sync Gateway versions prior to 3.2.6, where sensitive data may be logged insecurely.
What are the consequences of CVE-2025-52490?
The consequences of CVE-2025-52490 include potential unauthorized access to sensitive information if logs are accessed by malicious actors.
Are there any workarounds for CVE-2025-52490?
There are no known workarounds for CVE-2025-52490 other than to upgrade to the fixed version of Couchbase Sync Gateway.