ID:8616 - Exploit for Missing Authentication for Critical Function in CouchDB - CVE-2022-24706

 
Main Vulnerability Database Exploits ID:8616 - Exploit for Missing Authentication for Critical Function in CouchDB - CVE-2022-24706

ID:8616 - Exploit for Missing Authentication for Critical Function in CouchDB - CVE-2022-24706

Published: November 17, 2022


Vulnerability identifier: #VU62595
Vulnerability risk: High
CVE-ID: CVE-2022-24706
CWE-ID: CWE-306
Exploitation vector: Remote access
Vulnerable software:
CouchDB

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to gain full access to the application.

The vulnerability exists due to application in default configuration exposes a random network port, bound to all available interfaces in anticipation of clustered operation and/or runtime introspection. A remote attacker can connect to the application via the exposed port without authentication and gain admin privileges.


Remediation

Install updates from vendor's website.