#VU62595 Missing Authentication for Critical Function in CouchDB - CVE-2022-24706
Published: April 26, 2022 / Updated: November 17, 2022
CouchDB
Apache Foundation
Description
The vulnerability allows a remote attacker to gain full access to the application.
The vulnerability exists due to application in default configuration exposes a random network port, bound to all available interfaces
in anticipation of clustered operation and/or runtime introspection. A remote attacker can connect to the application via the exposed port without authentication and gain admin privileges.