CVE-2022-24706 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 92.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-09-15.
Description
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.51% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-1188 |
| On CISA KEV | yes — remediate by 2022-09-15 |
| Public exploit | yes |
| Published | 2022-04-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apache CouchDB Insecure Default Initialization of Resource Vulnerability |
|---|---|
| Added | 2022-08-25 |
| Due | 2022-09-15 |
| Vendor / product | Apache / CouchDB |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| apache | couchdb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache CouchDB 3.2.1 - Remote Code Execution (RCE) | 2022-05-11 |
References
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html
- http://www.openwall.com/lists/oss-security/2022/04/26/1
- http://www.openwall.com/lists/oss-security/2022/05/09/1
- http://www.openwall.com/lists/oss-security/2022/05/09/2
- http://www.openwall.com/lists/oss-security/2022/05/09/3
- http://www.openwall.com/lists/oss-security/2022/05/09/4
- https://docs.couchdb.org/en/3.2.2/setup/cluster.html
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00
- https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html
- http://www.openwall.com/lists/oss-security/2022/04/26/1
- http://www.openwall.com/lists/oss-security/2022/05/09/1
- http://www.openwall.com/lists/oss-security/2022/05/09/2
- http://www.openwall.com/lists/oss-security/2022/05/09/3
- http://www.openwall.com/lists/oss-security/2022/05/09/4
- https://docs.couchdb.org/en/3.2.2/setup/cluster.html
- https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00
- https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd
→ the Explorer · watch your stack · NVD