CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2017-11-14T20:00:00Z
Updated: 2024-09-16T18:48:31.205Z
Reserved: 2017-08-07T00:00:00
Link: CVE-2017-12636
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-11-14T20:29:00.247
Modified: 2024-11-21T03:09:56.593
Link: CVE-2017-12636
Redhat
No data.