CVE-2022-32192
Couchbase vulnerability analysis and mitigation

Overview

Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. The couchbase-cli spawns a very short-lived erlang process that has the master password as a process argument, meaning that if anyone gets the process list at that time they will have the master password. This only affects Couchbase Server clusters utilizing the Secrets Management feature (NVD, Couchbase Alerts).

Technical details

The vulnerability stems from a process management issue where the couchbase-cli tool exposes sensitive information through command-line arguments. Specifically, when spawning a short-lived erlang process, the master password for Secrets Management is passed as a process argument, making it temporarily visible in the process list (Couchbase Alerts). The vulnerability has been assigned a CVSS score of 5.5 (Medium severity) (NVD).

Impact

The vulnerability exposes the Secrets Management master password to potential attackers who can view the process list during the brief window when the erlang process is running. This could lead to unauthorized access to sensitive information managed by the Secrets Management feature (Couchbase Alerts).

Mitigation and workarounds

The vulnerability has been fixed in Couchbase Server versions 7.0.4 and 6.6.6. Users running affected versions should upgrade to these patched versions or later to resolve the issue (Couchbase Alerts).

Additional resources


SourceThis report was generated using AI

Related Couchbase vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-46619HIGH7.6
  • CouchbaseCouchbase
  • cpe:2.3:a:couchbase:couchbase_server
NoYesApr 30, 2025
CVE-2023-43768HIGH7.5
  • CouchbaseCouchbase
  • cpe:2.3:a:couchbase:couchbase_server
NoYesMar 27, 2024
CVE-2024-56178MEDIUM6.5
  • CouchbaseCouchbase
  • cpe:2.3:a:couchbase:couchbase_server
NoNoJan 27, 2025
CVE-2024-25673MEDIUM6.1
  • CouchbaseCouchbase
  • cpe:2.3:a:couchbase:couchbase_server
NoYesSep 19, 2024
CVE-2024-37034MEDIUM5.9
  • CouchbaseCouchbase
  • cpe:2.3:a:couchbase:couchbase_server
NoYesJul 26, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management