VulnerabilityModified
CVE-2010-3854
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MEDIUM 4.3EPSS 5.92%
Does this matter?
Lower severity and a low EPSS score (5.92%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 5.92% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/couchdb
- Source
- secalert@redhat.com
References
- http://mail-archives.apache.org/mod_mbox/couchdb-dev/201101.mbox/%3CC840F655-C8C5-4EC6-8AA8-DD223E39C34A%40apache.org%3E
- http://osvdb.org/70734
- http://secunia.com/advisories/43111Vendor Advisory
- http://www.securityfocus.com/archive/1/516058/100/0/threaded
- http://www.securityfocus.com/bid/46066
- http://www.securitytracker.com/id?1025013
- http://www.vupen.com/english/advisories/2011/0263Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65050
- http://mail-archives.apache.org/mod_mbox/couchdb-dev/201101.mbox/%3CC840F655-C8C5-4EC6-8AA8-DD223E39C34A%40apache.org%3E
- http://osvdb.org/70734
- http://secunia.com/advisories/43111Vendor Advisory
- http://www.securityfocus.com/archive/1/516058/100/0/threaded
- http://www.securityfocus.com/bid/46066
- http://www.securitytracker.com/id?1025013
- http://www.vupen.com/english/advisories/2011/0263Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65050
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.