Cross-Site Scripting Flaw in Apache CouchDB Web Administration Interface
CVE-2010-3854

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
2 February 2011

Summary

Multiple cross-site scripting vulnerabilities exist in the web administration interface (Futon) of Apache CouchDB versions ranging from 0.8.0 to 1.0.1. These flaws allow remote attackers to execute arbitrary web scripts or HTML by exploiting unspecified vectors. By leveraging these vulnerabilities, attackers can manipulate user sessions and potentially access sensitive information, thereby compromising the integrity of affected CouchDB installations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.