CVE-2017-12635
Last modified
CVE-2017-12635 is a vulnerability of currently unknown severity. Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. EPSS estimates a 99.84% chance of exploitation in the next 30 days.
Description
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Couchdb | < 1.7.0 |
| Apache | Couchdb | 2.0.0 |
References
- http://www.securityfocus.com/bid/101868Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201711-16Third Party Advisory
- http://www.securityfocus.com/bid/101868Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201711-16Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12635?
How severe is CVE-2017-12635?
How do I fix CVE-2017-12635?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-12629Remote code execution occurs in Apache Solr before 7.1 with …9.8
- CVE-2017-12630In Apache Drill 1.11.0 and earlier when submitting form from…
- CVE-2017-12631Apache CXF Fediz ships with a number of container-specific p…
- CVE-2017-12632A malicious host header in an incoming HTTP request could ca…
- CVE-2017-12633The camel-hessian component in Apache Camel 2.x before 2.19.…
- CVE-2017-12634The camel-castor component in Apache Camel 2.x before 2.19.4…
- CVE-2017-12636CouchDB administrative users can configure the database serv…
- CVE-2017-12637Directory traversal vulnerability in scheduler/ui/js/fffffff…7.5
- CVE-2017-12638Stack based buffer overflow in Ipswitch IMail server up to a…
- CVE-2017-12639Stack based buffer overflow in Ipswitch IMail server up to a…
- CVE-2017-1264IBM Security Guardium 10.0 does not prove or insufficiently …
- CVE-2017-12640ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability …8.8
Are you affected by CVE-2017-12635?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
