Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcpq-cj4x-h8mv

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

EPSS

Процентиль: 100%
0.8973
Высокий

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 9 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

CVSS3: 7.2
nvd
почти 9 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

CVSS3: 7.2
debian
почти 9 лет назад

CouchDB administrative users can configure the database server via HTT ...

EPSS

Процентиль: 100%
0.8973
Высокий

7.2 High

CVSS3

Дефекты

CWE-78