CVE-2022-24706
Summary
| CVE | CVE-2022-24706 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-26 10:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. |
Risk And Classification
EPSS: 0.943920000 probability, percentile 0.999730000 (date 2026-04-01)
CISA KEV: Listed on 2022-08-25; due 2022-09-15; ransomware use Unknown
Problem Types: CWE-1188
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | CouchDB |
| Name | Apache CouchDB Insecure Default Initialization of Resource Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00; https://nvd.nist.gov/vuln/detail/CVE-2022-24706 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache CouchDB Erlang Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| 2.2. Cluster Set Up — Apache CouchDB® 3.2 Documentation | MISC | docs.couchdb.org | |
| oss-security - Re: CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging | MLIST | www.openwall.com | |
| oss-security - CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging | MLIST | www.openwall.com | |
| Apache CouchDB 3.2.1 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 | MISC | lists.apache.org | |
| CouchDB, Erlang and cookies — RCE on default settings | by Konstantin Burov | Medium | medium.com | ||
| oss-security - Re: CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging | MLIST | www.openwall.com | |
| oss-security - Re: CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging | MLIST | www.openwall.com | |
| CouchDB, Erlang and cookies — RCE on default settings | by Konstantin Burov | Medium | MISC | medium.com | |
| oss-security - Re: CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: The Apache CouchDB Team would like to thank Alex Vandiver <[email protected]> for the report of this issue.
Legacy QID Mappings
- 730467 Apache CouchDB Remote Privilege Escalation Vulnerability