#VU84347 Code Injection in CouchDB - CVE-2023-45725

 

#VU84347 Code Injection in CouchDB - CVE-2023-45725

Published: December 12, 2023


Vulnerability identifier: #VU84347
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-45725
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
CouchDB
Software vendor:
Apache Foundation

Description

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper input validation. A remote user with access to design documents can insert specially crafted HTML code into the database and gain access to authorization or session cookie headers when the victim opens the design documents.


Remediation

Install updates from vendor's website.

External links