Critical severity9.8CISA KEVNVD Advisory· Published Apr 26, 2022· Updated Jun 17, 2026
CVE-2022-24706
CVE-2022-24706
Description
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Apache Software Foundation/Apache CouchDBv5Range: Apache CouchDB
Patches
Vulnerability mechanics
References
11- www.openwall.com/lists/oss-security/2022/05/09/2nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2022/05/09/3nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2022/05/09/4nvdMailing ListPatchThird Party Advisory
- packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcdnvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2022/04/26/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/05/09/1nvdMailing ListThird Party Advisory
- lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00nvdMailing ListVendor Advisory
- docs.couchdb.org/en/3.2.2/setup/cluster.htmlnvdBroken LinkProduct
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.