Directory Traversal Vulnerability in MochiWeb Affecting Apache CouchDB
CVE-2012-5641

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
18 March 2014

What is CVE-2012-5641?

A directory traversal vulnerability exists in the partition2 function of mochiweb_util.erl in MochiWeb versions prior to 2.4.0. This vulnerability impacts Apache CouchDB versions earlier than 1.0.4 and also affects 1.1.x and 1.2.x versions prior to their respective updates. By exploiting this flaw, remote attackers can manipulate the URI to access arbitrary files on the server, facilitated by the use of unescaped backslashes. This concern highlights the need for robust input validation and security measures within web applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2012-5641 : Directory Traversal Vulnerability in MochiWeb Affecting Apache CouchDB