Junglewise Threat Intelligence

CVE-2022-24706: Apache CouchDB Insecure Default Initialization of Resource Vulnerability

CVE-2022-24706 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-08-25

Vendors: Apache.

Executive brief

Apache CouchDB contains an insecure default initialization of resource vulnerability where an improperly secured default installation allows unauthenticated attackers to gain administrative privileges. This occurs because the default configuration may expose the Erlang distribution port without a secure cookie, enabling remote code execution.

Affected products

  • Apache CouchDB prior to 3.2.2

Timeline

  • 2022-04-26: disclosed: Initial public disclosure via oss-security mailing list
  • 2022-05-09: patched: Patches and version 3.2.2 released
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog