CVE-2018-17188

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-17188
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-17188.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-17188
Related
Published
2019-01-02T14:29:00Z
Modified
2025-01-14T07:25:13.123355Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating system as the CouchDB user. Together with other vulnerabilities, it allowed full system entry for unauthenticated users. Rather than waiting for new vulnerabilities to be discovered, and fixing them as they come up, the CouchDB development team decided to make changes to avoid this entire class of vulnerabilities.

References

Affected packages

Git / github.com/apache/couchdb

Affected ranges

Type
GIT
Repo
https://github.com/apache/couchdb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.1.0

Other

fauxton