VDB

CVE-2017-12636

CVE-2017-12636 PUBLISHED KEV CVSS 7.199999809265137 HIGH

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

EPSS 89.73% · 99.8th percentile

Risk Scores

CVSS 3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
89.73%
99.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTScouchdb0, 1.6.0-0ubuntu7

Timeline

  • CVE Published
  • Nov 30, 2017 PoC Published
  • Mar 13, 2018 PoC Published
  • Apr 23, 2018 PoC Published
  • Jun 20, 2018 PoC Published
  • Jun 20, 2018 PoC Published
  • Jun 25, 2018 PoC Published
  • Jul 12, 2018 PoC Published
  • Jul 12, 2018 PoC Published
  • Jul 13, 2018 PoC Published
  • Oct 9, 2020 PoC Published
  • Oct 9, 2020 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›