Vulnerabilities > Apache > Couchdb > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-04-26 CVE-2022-24706 Insecure Default Initialization of Resource vulnerability in Apache Couchdb
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.
network
low complexity
apache CWE-1188
critical
9.8
2020-05-20 CVE-2020-1955 Missing Authentication for Critical Function vulnerability in Apache Couchdb 3.0.0
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`.
network
low complexity
apache CWE-306
critical
9.8
2017-11-14 CVE-2017-12635 Improper Privilege Management vulnerability in Apache Couchdb
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users.
network
low complexity
apache CWE-269
critical
9.8