ZeroHour

CVE-2022-24706

KEV PoC ×3

Apache CouchDB Insecure Default Initialization of Resource Vulnerability

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CISA Known Exploited Vulnerability
Affected
Apache CouchDB
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apache
Products
couchdb
Weakness
CWE-1188
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news