Back

HIGH

CouchDB administrative users can configure the database server via HTTP(S)

Published Nov 14, 2017

Description

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Nov 14, 2017
Updated Sep 16, 2024
Reserved Aug 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a