The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
History

Wed, 18 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-297
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Description The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-18T00:00:00.000Z

Updated: 2025-06-18T14:47:35.181Z

Reserved: 2025-05-30T00:00:00.000Z

Link: CVE-2025-49015

cve-icon Vulnrichment

Updated: 2025-06-18T14:46:56.864Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-18T14:15:44.870

Modified: 2025-06-23T20:16:59.783

Link: CVE-2025-49015

cve-icon Redhat

No data.