
We found results for “”
CVE-2025-49015
Good to know:


Date: June 17, 2025
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Improper Validation of Certificate with Host Mismatch
CWE-297Top Fix

Upgrade Version
Upgrade to version CouchbaseNetClient - 3.7.1;Couchbase.NetClient - 3.7.1;https://github.com/couchbase/couchbase-net-client.git - 3.7.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |