CVE-2022-24706

9.8CRITICAL

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommen

Опубликовано: 4/26/2022Обновлено: 10/28/2025

Известная эксплуатируемая уязвимость CISA

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

Требуемое действие:

Apply updates per vendor instructions.

Срок:

2022-09-15

Описание

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

ИИ-АнализНа базе ИИ

Затронутые продукты

apachecouchdb

Доступные эксплойты (1)

Ссылки