PT-2018-18377 · Apache · Apache Couchdb
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache CouchDB versions prior to 1.7.2
Apache CouchDB versions prior to 2.1.2
Description
Administrative users can configure the database server via HTTP(S). Insufficient validation of configuration settings provided through the HTTP API allows an administrator to bypass the blacklist of restricted settings. This enables the user to escalate privileges to the level of the operating system user running the service, resulting in arbitrary remote code execution.
Recommendations
Upgrade to version 1.7.2.
Upgrade to version 2.1.2.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Couchdb