REDHAT-BUG-624764: CSRF
Apache CouchDB prior to 0.11.2 and 1.0.1 are vulnerable to cross site request forgery (CSRF) attacks. A malicious web site can POST arbitrary JavaScript code to wellknown CouchDB installation URLs and make the browser execute the injected JavaScript in the security context of CouchDB's admin interface Futon.
This issue has been assigned the name CVE-2010-2234.
References:
http://seclists.org/fulldisclosure/2010/Aug/199
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-624764?
The severity of REDHAT-BUG-624764 is high due to the potential for cross site request forgery (CSRF) attacks.
How do I fix REDHAT-BUG-624764?
To fix REDHAT-BUG-624764, upgrade Apache CouchDB to version 0.11.2 or later.
What versions of CouchDB are affected by REDHAT-BUG-624764?
Apache CouchDB versions prior to 0.11.2 and 1.0.1 are vulnerable to REDHAT-BUG-624764.
What type of attack does REDHAT-BUG-624764 involve?
REDHAT-BUG-624764 involves cross site request forgery (CSRF) attacks enabling malicious JavaScript execution.
Who is responsible for addressing REDHAT-BUG-624764?
System administrators and users of Apache CouchDB are responsible for addressing REDHAT-BUG-624764 by applying the necessary updates.