Executive brief
Couchbase Sync Gateway, a component used to synchronize data between mobile devices and the cloud, was found to be leaking user passwords in plain text within its log files. This occurs even when redaction features are enabled, potentially allowing anyone with access to the logs to see sensitive credentials. This could lead to unauthorized account access and data breaches if log files are improperly secured or shared.
Technical details
Couchbase Sync Gateway prior to version 3.2.6 contains a sensitive information disclosure vulnerability (CWE-319). The application logs cleartext passwords in 'sgcollect_info_options.log' and 'sync_gateway.log', even when log redaction is enabled. An attacker with access to these log files—or potentially via network-based log collection services—could obtain administrative or user credentials. This issue is resolved in version 3.2.6. The CVSS score of 7.3 reflects a network attack vector, though exploitation typically requires the ability to view or intercept log output.
Affected products
- Couchbase Sync Gateway < 3.2.6
Timeline
- 2025-07-29: disclosed
- 2025-07-29: advisory
- 2025-07-29: patched: Version 3.2.6 released