CVE-2023-50782: Couchbase Server
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Affected products
- Couchbase Couchbase Server: version 7.6.0 only; version 7.6.1 only
- Cryptography.io Cryptography: before 42.0.0 (fixed in 42.0.0)
- Red Hat Ansible Automation Platform: version 2.0 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Update Infrastructure: version 4 only
Published 2024-02-05. Last modified 2026-06-17.