CVE-2022-24706

9.8CRITICAL

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommen

发布于: 4/26/2022更新于: 10/28/2025

CISA已知被利用漏洞

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

所需操作:

Apply updates per vendor instructions.

截止日期:

2022-09-15

描述

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

AI分析AI驱动

受影响产品

apachecouchdb

可用漏洞利用 (1)

参考资料