Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12636

Опубликовано: 14 нояб. 2017
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 9
CVSS3: 7.2

Описание

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

РелизСтатусПримечание
artful

ignored

end of life
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps-legacy/xenial

needed

esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

Показывать по

EPSS

Процентиль: 100%
0.8973
Высокий

9 Critical

CVSS2

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
почти 9 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

CVSS3: 7.2
debian
почти 9 лет назад

CouchDB administrative users can configure the database server via HTT ...

CVSS3: 7.2
github
больше 4 лет назад

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

EPSS

Процентиль: 100%
0.8973
Высокий

9 Critical

CVSS2

7.2 High

CVSS3