← All CVEs

CVE-2017-12636

high · 7.2

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

7.2
CVSS
89.7%
EPSS (exploit prob.)
100th
EPSS percentile
2017-11-14
Published

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
apachecouchdb< 1.7.0
apachecouchdb2.0.0
apachecouchdb2.0.0
apachecouchdb2.0.0
apachecouchdb2.0.0
apachecouchdb2.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12636