Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
BID:101868
Info
Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 101868 |
| Class: | Design Error |
| CVE: |
CVE-2017-12635 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2017 12:00AM |
| Updated: | Dec 19 2017 10:37PM |
| Credit: | Max Justicz |
| Vulnerable: |
Apache CouchDB 2.1 Apache CouchDB 2.0 Apache CouchDB 1.6 |
| Not Vulnerable: |
Apache CouchDB 2.1.1 Apache CouchDB 1.7 |
Discussion
Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
Apache CouchDB is prone to a remote privilege-escalation vulnerability.
A remote attacker can exploit this issue to bypass certain restrictions and gain elevated privileges.
Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1 are vulnerable.
Apache CouchDB is prone to a remote privilege-escalation vulnerability.
A remote attacker can exploit this issue to bypass certain restrictions and gain elevated privileges.
Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1 are vulnerable.
Exploit / POC
Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
References:
References:
- Apache Homepage (Apache)
- Apache CouchDB CVE-2017-12635 and CVE-2017-12636 (Apache)