vendor:
CouchDB
by:
Konstantin Burov
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: CouchDB
Affected Version From: 3.2.1 and below
Affected Version To: 3.2.2001
Patch Exists: YES
Related CWE: CVE-2022-24706
CPE: a:apache:couchdb:3.2.1
Platforms Tested: Kali 2021.2
2022
Apache CouchDB 3.2.1 – Remote Code Execution (RCE)
Apache CouchDB is vulnerable to Remote Code Execution (RCE) due to a flaw in the Erlang Cookie. An attacker can exploit this vulnerability by sending a crafted payload to the Erlang Port Mapper Daemon (EPMD) on port 4369. This payload will allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
The user should update to the latest version of Apache CouchDB to mitigate this vulnerability.