VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Apr 26, 2022· Updated Jun 17, 2026

CVE-2022-24706

CVE-2022-24706

Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Apache/Couchdb2 versions
    cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*range: <3.2.2
    • (no CPE)range: <3.2.2
  • osv-coords
    Range: < 3.2.2
  • Apache Software Foundation/Apache CouchDBv5
    Range: Apache CouchDB

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.