Apache
Apache Couchdb: vulnerabilidades y CVE
Apache Couchdb tiene 21 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses1
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-24706 | Crítica (9.8) | 93% | ⚠ Explotación activa | 26 abr 2022 | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-46424 | Media (4.2) | 0.25% | — | 27 may 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate the corresponding… |
| CVE-2023-45725 | Media (5.7) | 1.2% | — | 13 dic 2023 | Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. An attacker can leak the session component using an HTML-like… |
| CVE-2023-26268 | Media (5.3) | 1.4% | — | 2 may 2023 | This doesn't affect map/reduce or search (Dreyfus) index functions. Users are recommended to upgrade to a version that is no longer affected by this issue (Apache CouchDB 3.3.2 or 3.2.3). Workaround: Avoid using design… |
| CVE-2022-24706 | Crítica (9.8) | 93% | ⚠ Explotación activa | 26 abr 2022 | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for… |
| CVE-2021-38295 | Alta (7.3) | 2.5% | — | 14 oct 2021 | In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin… |
| CVE-2020-1955 | Crítica (9.8) | 1.8% | — | 20 may 2020 | CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing… |
| CVE-2018-17188 | Alta (7.2) | 3.2% | — | 2 ene 2019 | Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating… |
| CVE-2018-14889 | Alta (7.8) | 0.56% | — | 21 sept 2018 | CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. |
| CVE-2018-11769 | Alta (7.2) | 8.2% | — | 8 ago 2018 | CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB… |
| CVE-2018-8007 | Alta (7.2) | 12% | — | 11 jul 2018 | Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB… |
| CVE-2016-8742 | Alta (7.8) | 2.0% | — | 12 feb 2018 | The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user… |
| CVE-2017-12636 | Alta (7.2) | 90% | — | 14 nov 2017 | CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an… |
| CVE-2017-12635 | Crítica (9.8) | 100% | — | 14 nov 2017 | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for… |
| CVE-2012-5649 | Media (6.8) | 6.6% | — | 23 may 2014 | Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash. |
| CVE-2014-2668 | Media (5) | 22% | — | 28 mar 2014 | Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids. |
| CVE-2012-5650 | Media (4.3) | 3.8% | — | 18 mar 2014 | Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified… |
| CVE-2012-5641 | Media (5) | 8.9% | — | 18 mar 2014 | Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to… |
| CVE-2010-3854 | Media (4.3) | 5.9% | — | 2 feb 2011 | Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified… |
| CVE-2010-2953 | Media (6.9) | 0.60% | — | 14 sept 2010 | Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges via a crafted shared library in the current working directory. |
| CVE-2010-2234 | Media (6.8) | 1.8% | — | 19 ago 2010 | Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL. |
| CVE-2010-0009 | Media (4.3) | 5.3% | — | 5 abr 2010 | Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.