CVE-2010-3854
published 2011-02-02CVE-2010-3854: Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.92%
92.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
| apache | couchdb | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3854 couchdb: XSS vulnerability
bugzilla·2011-01-31·CVSS 4.3
CVE-2010-3854 [MEDIUM] CVE-2010-3854 couchdb: XSS vulnerability
CVE-2010-3854 couchdb: XSS vulnerability
A cross-site scripting flaw was reported in Apache CouchDB 0.8.0 to 1.0.1 [1]. This flaw has been corrected in version 1.0.2.
Due to inadequate validation of request parameters and cookie data in Futon, CouchDB's web-based administration UI, a malicious site can execute arbitrary code in the context of a user's browsing session.
[1] http://mail-archives.apache.org/mod_mbox/couchdb-dev/201101.mbox/%[email protected]%3e
Discussion:
Created couchdb tracking bugs for this issue
Affects: fedora-all [bug 674145]
Affects: epel-all [bug 674146]
---
Almost done with this - fixed builds were pulled in F-14, F-15, EL-6.
Unfortunately, it seems that it couldn't be easy to fix EL-5 (it will require upgrade from 0.11.2 to
Bugzilla
CVE-2010-3854 couchdb: XSS vulnerability [fedora-all]
bugzilla·2011-01-31·CVSS 4.3
CVE-2010-3854 [MEDIUM] CVE-2010-3854 couchdb: XSS vulnerability [fedora-all]
CVE-2010-3854 couchdb: XSS vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=674144
Please note: this issue affects multiple supported versions o
Bugzilla
CVE-2010-3854 couchdb: XSS vulnerability [epel-all]
bugzilla·2011-01-31·CVSS 4.3
CVE-2010-3854 [MEDIUM] CVE-2010-3854 couchdb: XSS vulnerability [epel-all]
CVE-2010-3854 couchdb: XSS vulnerability [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=674144
Please note: this issue affects multiple supported versions of
http://mail-archives.apache.org/mod_mbox/couchdb-dev/201101.mbox/%3CC840F655-C8C5-4EC6-8AA8-DD223E39C34A%40apache.org%3Ehttp://osvdb.org/70734http://secunia.com/advisories/43111http://www.securityfocus.com/archive/1/516058/100/0/threadedhttp://www.securityfocus.com/bid/46066http://www.securitytracker.com/id?1025013http://www.vupen.com/english/advisories/2011/0263https://exchange.xforce.ibmcloud.com/vulnerabilities/65050http://mail-archives.apache.org/mod_mbox/couchdb-dev/201101.mbox/%3CC840F655-C8C5-4EC6-8AA8-DD223E39C34A%40apache.org%3Ehttp://osvdb.org/70734http://secunia.com/advisories/43111http://www.securityfocus.com/archive/1/516058/100/0/threadedhttp://www.securityfocus.com/bid/46066http://www.securitytracker.com/id?1025013http://www.vupen.com/english/advisories/2011/0263https://exchange.xforce.ibmcloud.com/vulnerabilities/65050
2011-02-02
Published