Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12636

Опубликовано: 14 нояб. 2017
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Критический

Описание

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*
Версия до 1.7.0 (исключая)
cpe:2.3:a:apache:couchdb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:couchdb:2.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:couchdb:2.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:couchdb:2.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:apache:couchdb:2.0.0:rc4:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.9369
Критический

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 8 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

CVSS3: 7.2
debian
около 8 лет назад

CouchDB administrative users can configure the database server via HTT ...

CVSS3: 7.2
github
больше 3 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

EPSS

Процентиль: 100%
0.9369
Критический

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78