peter bassill · operator
$ cve CVE-2017-12636 JSON

CVE-2017-12636 EXPLOIT

7.2
HIGH · CVSS 3.0 · EPSS 89.7% (pctl 100)

Patch early

A public exploit exists.

Description

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

Scoring

CVSS7.2 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS89.73% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2017-11-14
Last modified2026-06-17

Affected (1)

VendorProduct
apachecouchdb

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD