CVE-2017-12636

UnknownEPSS 90.60%

Last modified

CVE-2017-12636 is a vulnerability of currently unknown severity. CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. EPSS estimates a 90.60% chance of exploitation in the next 30 days.

Description

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

Metrics

EPSS Probability
90.60%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheCouchdb< 1.7.0
ApacheCouchdb2.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-12636?
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.
How severe is CVE-2017-12636?
Severity scoring for CVE-2017-12636 is pending analysis. The EPSS model estimates a 90.60% probability of exploitation in the next 30 days.
How do I fix CVE-2017-12636?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-12636?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST