Latest apache couchdb Vulnerabilities

Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design Documents
Apache CouchDB<=3.3.2
Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: * validate_doc_update * l...
Apache CouchDB<3.2.3
Apache CouchDB>=3.3.0<3.3.2
Ibm Cloudant<=8349
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Apache CouchDB<3.2.2
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via...
Apache CouchDB<3.1.2
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the ...
Apache CouchDB=3.0.0
Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the unde...
Apache CouchDB<2.3.0
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
Apache CouchDB
Vectra Cognito<4.3
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possibl...
Apache CouchDB<2.2.0
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for ...
Apache CouchDB<=1.7.1
Apache CouchDB>=2.0.0<=2.1.1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203