Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Unauthenticated Remote Code Execution in Apache CouchDB CVE-2022-24706 #517

Open
frkngksl opened this issue Jul 13, 2024 · 0 comments
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.

Comments

@frkngksl
Copy link
Contributor

Hi,

I want to implement a detection plugin for CVE-2022-24706

Software Detail: Apache CouchDB ™ lets you access your data where you need it. The Couch Replication Protocol is implemented in a variety of projects and products that span every imaginable computing environment from globally distributed server-clusters, over mobile phones to web browsers.

Vulnerability Detail: In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

Ref: https://medium.com/@ahmetsabrimert/apache-couchdb-cve-2022-24706-rce-exploits-548fe52f8c02
Ref: https://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html

@frkngksl frkngksl changed the title AI PRP: Unauthenticated Remote Code Execution in Apache CouchDB CVE-2022-24706 PRP: Unauthenticated Remote Code Execution in Apache CouchDB CVE-2022-24706 Jul 13, 2024
@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Jul 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.
Projects
None yet
Development

No branches or pull requests

2 participants