SCA: security update for couchbase (GHSA-9266-j9v3-q4j5)

critical Tenable Self-Hosted Container Security Plugin ID 421797

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified
when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync
Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin
credentials provided to the Admin REST API are ignored, resulting in privilege escalation for
unauthenticated users. The Public REST API is not impacted by this issue. A workaround is to replace X.509
certificate based authentication with Username and Password authentication inside the bootstrap
configuration. (CVE-2022-32563)

See Also

https://github.com/advisories/GHSA-9266-j9v3-q4j5

Plugin Details

Severity: Critical

ID: 421797

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-32563

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/11/2022

Vulnerability Publication Date: 6/10/2022

Reference Information

CVE: CVE-2022-32563

cwe: CWE-295