Couchbase / Sync Gateway
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-52490 | An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted a… | HIGH | 7.3 | Jul 29, 2025 |
| CVE-2022-32563 | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from… | CRITICAL | 9.3 | Jun 10, 2022 |
| CVE-2021-43963 | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were insecurely b… | HIGH | 8.1 | Dec 7, 2021 |
| CVE-2020-9041 | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the… | HIGH | 7.5 | Jun 8, 2020 |
| CVE-2019-9039 | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensiti… | CRITICAL | 9.8 | Jun 26, 2019 |
Showing 1 to 5 of 5 CVEs