Permissions, Privileges, and Access Controls in CouchDB - CVE-2018-17188
Published: January 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to CouchDB allows runtime-configuration of key components of the database. A CouchDB administrator can gain access to operating system components and execute code on the system with privileges of the CouchDB system user account.
Affected software
Fedora
couchdb
How to mitigate CVE-2018-17188
couchdb - addressed in versions 3.0.0-1.fc31, 3.0.0-1.fc32