Skip to main content

Vendor/product archive

apache / couchdb CVEs

Beta · best-effort

20 CVEs tagged to apache / couchdb3 Critical, 7 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2023-45725

Published Dec 13, 2023

Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. These design document…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26268

Published May 2, 2023

Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: * valida…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24706

Published Apr 26, 2022

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-38295

Published Oct 14, 2021

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1955

Published May 20, 2020

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17188

Published Jan 2, 2019

Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11769

Published Aug 8, 2018

CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HT…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8007

Published Jul 11, 2018

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8742

Published Feb 12, 2018

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent direc…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12636

Published Nov 14, 2017

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequent…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12635

Published Nov 14, 2017

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5649

Published May 23, 2014

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2668

Published Mar 28, 2014

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5650

Published Mar 18, 2014

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5641

Published Mar 18, 2014

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3854

Published Feb 2, 2011

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2953

Published Sep 14, 2010

Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges via a crafted shared library…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2234

Published Aug 19, 2010

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0009

Published Apr 5, 2010

Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1