CVE-2022-24706

9.8CRITICAL

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommen

公開日: 4/26/2022更新日: 10/28/2025

CISA既知の悪用された脆弱性

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

必要な対応:

Apply updates per vendor instructions.

期限:

2022-09-15

説明

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

AI分析AIによる分析

影響を受ける製品

apachecouchdb

利用可能なエクスプロイト (1)

参照