Vulnerability CVE-2022-24706


Published: 2022-04-26

Description:
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

See advisories in our WLB2 database:
Topic
Author
Date
High
Apache CouchDB 3.2.1 Remote Code Execution (RCE)
Konstantin Burov
12.05.2022
High
Apache CouchDB Erlang Remote Code Execution
1F98D
02.11.2022

 References:
https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00
https://docs.couchdb.org/en/3.2.2/setup/cluster.html

Copyright 2024, cxsecurity.com

 

Back to Top