Missing Authentication for Critical Function in CouchDB - CVE-2022-24706
Published: April 26, 2022 / Updated: November 17, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain full access to the application.
The vulnerability exists due to application in default configuration exposes a random network port, bound to all available interfaces
in anticipation of clustered operation and/or runtime introspection. A remote attacker can connect to the application via the exposed port without authentication and gain admin privileges.
Affected software
IBM Cloud Pak for Multicloud Management
Planning Analytics Local
How to mitigate CVE-2022-24706
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3
Links to Public Exploits and PoC-codes
- Exploit #8616 - CVE-2022-24706-POC (CouchDB & EPMD RCE exploit) (November 17, 2022)
- Exploit #8555 - Apache Couchdb Erlang RCE (November 1, 2022)
- Exploit #8346 - CVE-2022-24706-CouchDB-Exploit () (September 6, 2022)
- Exploit #7874 - CVE-2022-24706-CouchDB-Exploit (Apache CouchDB 3.2.1 - Remote Code Execution (RCE)) (May 23, 2022)
- Exploit #7797 - Apache CouchDB 3.2.1 - Remote Code Execution (RCE) (May 13, 2022)
- Exploit #7764 - Apache CouchDB 3.2.1 Remote Code Execution (May 11, 2022)