CVE-2022-24706
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache CouchDB Insecure Default Initialization of Resource Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 93% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-1188
מוצרים מושפעים
apache: couchdb
קישורים
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 Mailing ListVendor Advisory
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/2 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/3 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/4 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/2 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/3 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/4 Mailing ListPatchThird Party Advisory
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-E… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-… ExploitThird Party AdvisoryVDB Entry