CVE-2022-24706
Remote Code Execution Vulnerability in Packaging
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 10, 2022
- Published Date
- April 26, 2022
- Last Updated
- January 29, 2025
- Vendor
- Apache Software Foundation
- Product
- Apache CouchDB
- Description
- In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00
https://docs.couchdb.org/en/3.2.2/setup/cluster.html
http://www.openwall.com/lists/oss-security/2022/04/26/1
http://www.openwall.com/lists/oss-security/2022/05/09/1
http://www.openwall.com/lists/oss-security/2022/05/09/3
http://www.openwall.com/lists/oss-security/2022/05/09/4
http://www.openwall.com/lists/oss-security/2022/05/09/2
http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html
https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd
http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-08-25 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apache_couchdb_erlang_rce.rb | 2025-04-29 11:01:20 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2022/CVE-2022-24706.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
apache_couchdb_erlang_rce
Type: metasploit • Created: Unknown
Metasploit module for CVE-2022-24706
sadshade/CVE-2022-24706-CouchDB-Exploit
Type: github • Created: 2022-05-20 04:28:51 UTC • Stars: 29
Apache CouchDB 3.2.1 - Remote Code Execution (RCE)