Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxc9-8m8h-9cp6

Опубликовано: 27 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

EPSS

Процентиль: 100%
0.94215
Критический

9.8 Critical

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVSS3: 9.8
nvd
почти 4 года назад

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVSS3: 9.8
debian
почти 4 года назад

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly ...

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость системы управления базами данных CouchDB, связанная с небезопасной инициализацией ресурса, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 100%
0.94215
Критический

9.8 Critical

CVSS3

Дефекты

CWE-1188