← Back

CVE-2017-12636

nvd nist
Published: Nov 14, 2017Modified: May 13, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

Affected (6)

Products: Apache: Couchdb
1 product
Couchdb
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 1.7.0
Version 2.0.0
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.0 rc4

Timeline

No history available yet.