CVE-2022-24706
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 92.51% probability · 100th percentile
- CISA KEV
- Listed 25 August 2022 · due 15 September 2022
- Weakness
- CWE-1188
- Affected
- apache/couchdb
- Source
- security@apache.org
CISA notes
Apply updates per vendor instructions. https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00; https://nvd.nist.gov/vuln/detail/CVE-2022-24706
References
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/04/26/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/3Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/4Mailing List, Patch, Third Party Advisory
- https://docs.couchdb.org/en/3.2.2/setup/cluster.htmlBroken Link, Product
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00Mailing List, Vendor Advisory
- https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcdExploit, Third Party Advisory
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/04/26/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/3Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/05/09/4Mailing List, Patch, Third Party Advisory
- https://docs.couchdb.org/en/3.2.2/setup/cluster.htmlBroken Link, Product
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00Mailing List, Vendor Advisory
- https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcdExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24706US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.