CVE-2022-24706

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:44

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd', 'name': 'https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd -

21 Nov 2022, 19:28

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html - (MISC) http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html - Exploit, Third Party Advisory (MISC) http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry

02 Nov 2022, 17:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html -

30 Sep 2022, 13:03

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html - (MISC) http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html - Exploit, Third Party Advisory
References (MISC) https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd - (MISC) https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd - Exploit, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/1 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/1 - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/2 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/2 - Mailing List, Patch, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/3 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/3 - Mailing List, Patch, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/4 - Mailing List, Patch, Third Party Advisory

13 Jul 2022, 18:15

Type Values Removed Values Added
References
  • (MISC) https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd -

11 May 2022, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html -

09 May 2022, 15:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/3 -
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/1 -
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/2 -
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/05/09/4 -

06 May 2022, 13:10

Type Values Removed Values Added
References (MISC) https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 - (MISC) https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 - Mailing List, Vendor Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/04/26/1 - (MLIST) http://www.openwall.com/lists/oss-security/2022/04/26/1 - Mailing List, Third Party Advisory
References (MISC) https://docs.couchdb.org/en/3.2.2/setup/cluster.html - (MISC) https://docs.couchdb.org/en/3.2.2/setup/cluster.html - Product
CWE CWE-1188
CPE cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*
First Time Apache couchdb
Apache
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8

26 Apr 2022, 15:46

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/04/26/1 -

26 Apr 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-26 10:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24706

Mitre link : CVE-2022-24706

CVE.ORG link : CVE-2022-24706


JSON object : View

Products Affected

apache

  • couchdb
CWE
CWE-1188

Insecure Default Initialization of Resource