CVE-2017-12636
Last modified
CVE-2017-12636 is a vulnerability of currently unknown severity. CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. EPSS estimates a 90.60% chance of exploitation in the next 30 days.
Description
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Couchdb | < 1.7.0 |
| Apache | Couchdb | 2.0.0 |
References
- https://security.gentoo.org/glsa/201711-16Third Party Advisory
- https://security.gentoo.org/glsa/201711-16Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12636?
How severe is CVE-2017-12636?
How do I fix CVE-2017-12636?
Are you affected by CVE-2017-12636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
