Executive brief
Apache CouchDB contains an insecure default initialization of resource vulnerability where an improperly secured default installation allows unauthenticated attackers to gain administrative privileges. This occurs because the default configuration may expose the Erlang distribution port without a secure cookie, enabling remote code execution.
Affected products
- Apache CouchDB prior to 3.2.2
Timeline
- 2022-04-26: disclosed: Initial public disclosure via oss-security mailing list
- 2022-05-09: patched: Patches and version 3.2.2 released
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog