SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-24706

Apache CouchDB Insecure Default Initialization of Resource Vulnerability

KEVCRITICAL 9.8EPSS 92.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
92.51% probability · 100th percentile
CISA KEV
Listed 25 August 2022 · due 15 September 2022
Weakness
CWE-1188
Affected
apache/couchdb
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00; https://nvd.nist.gov/vuln/detail/CVE-2022-24706

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.