CouchDB Database Configuration Vulnerability in Administration Access
CVE-2018-17188
7.2HIGH
Summary
Prior to version 2.3.0, CouchDB permitted runtime configuration of critical database components, allowing admin users to gain unauthorized access to the underlying operating system as the CouchDB user. In conjunction with other vulnerabilities, this configuration issue could potentially enable unauthenticated users to achieve full system access. To mitigate this risk, the CouchDB development team implemented significant changes in later releases, effectively closing off this vector for attack and enhancing overall system security.
Affected Version(s)
Apache CouchDB All
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved