QID 730467
Date Published: 2022-05-02
QID 730467: Apache CouchDB Remote Privilege Escalation Vulnerability
Apache CouchDB is a free open source document-oriented database written in the Erlang programming language.
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.
Affected Versions:
Apache CouchDB versions prior to 3.2.2
QID Detection Logic(Remote)
It checks for vulnerable version of Apache CouchDB by sending a GET request to the target and matches the vulnerable version.
An attacker can access an improperly secured default installation without authenticating and gain admin privileges.
Solution
The vendor has already released the patch to fix the vulnerability. Customers are advised to upgrade to Apache CouchDB.
Vendor References
- Apache CouchDB Remote Privilege Escalation -
lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00
CVEs related to QID 730467
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache CouchDB |
|