PT-2018-18377 · Apache · Apache Couchdb

·

CVE-2018-8007

·

Published

2018-07-11

·

Updated

2026-07-02

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache CouchDB versions prior to 1.7.2 Apache CouchDB versions prior to 2.1.2
Description Administrative users can configure the database server via HTTP(S). Insufficient validation of configuration settings provided through the HTTP API allows an administrator to bypass the blacklist of restricted settings. This enables the user to escalate privileges to the level of the operating system user running the service, resulting in arbitrary remote code execution.
Recommendations Upgrade to version 1.7.2. Upgrade to version 2.1.2.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8007
SUSE-SU-2018:2578-1
SUSE-SU-2018:2765-1

Affected Products

Apache Couchdb