Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
BID:103036
Info
Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
| Bugtraq ID: | 103036 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12636 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2017 12:00AM |
| Updated: | Nov 14 2017 12:00AM |
| Credit: | Joan Touzet |
| Vulnerable: |
Apache CouchDB 2.1 Apache CouchDB 2.0 |
| Not Vulnerable: |
Apache CouchDB 2.1.1 Apache CouchDB 1.7 |
Discussion
Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
Apache CouchDB is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1 are vulnerable.
Apache CouchDB is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1 are vulnerable.
Exploit / POC
Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].