CVE-2022-24706

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

Scoring

Severity
CRITICAL
CVSS base score
9.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS probability
94.39%
CISA KEV
Known exploited vulnerability
CWE
CWE-1188
Published
2022-04-26
Last modified
2026-09-16

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs