CVE-2022-24706: Apache CouchDB: Remote Code Execution Vulnerability in Packaging

2022-04-26 Thread Jan Lehnardt
Severity: critical Description: An attacker can access an improperly secured default installation without authenticating and gain admin privileges. 1. CouchDB opens a random network port, bound to all available interfaces in anticipation of clustered operation and/or runtime introspection. A

CVE-2022-24706: Apache CouchDB Remote Privilege Escalation

2022-04-26 Thread Jan Lehnardt
Description === An attacker can access an improperly secured default installation without authenticating and gain admin privileges. 1. CouchDB opens a random network port, bound to all available interfaces in anticipation of clustered operation and/or runtime introspection. A