Permissions, Privileges, and Access Controls in CouchDB - CVE-2018-17188

 

Permissions, Privileges, and Access Controls in CouchDB - CVE-2018-17188

Published: January 7, 2019


Vulnerability identifier: #VU16815
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17188
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to CouchDB allows runtime-configuration of key components of the database. A CouchDB administrator can gain access to operating system components and execute code on the system with privileges of the CouchDB system user account.


Affected software

CouchDB
Fedora
couchdb

How to mitigate CVE-2018-17188

Install updates from vendor's website.

CouchDB - update to 2.3.0
couchdb - addressed in versions 3.0.0-1.fc31, 3.0.0-1.fc32

External References

Related Security Bulletins