CVE-2018-8007
published 2018-07-11CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration…
PriorityP277high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
11.68%
95.6th percentile
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | couchdb | < 2.2.0 | 2.2.0 |
| apache | couchdb | <= 1.7.1 | — |
| apache | couchdb | 2.0.0 – 2.1.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·CVE-2018-8007 exploitation requires authenticated CouchDB administrator credentials — this is a privilege escalation from admin to OS user, not an unauthenticated RCE; detections should focus on suspicious HTTP API configuration changes by admin accounts ↗
- ·CVE-2018-8007 was subsequently bypassed by CVE-2018-11769, which itself bypassed mitigations for both CVE-2017-12636 and CVE-2018-8007 — patching to 1.7.2/2.1.2 alone may be insufficient if CVE-2018-11769 is also applicable ↗
- ·The IP 176.65.139[.]204 is attributed to RustDuck botnet delivery broadly (20+ CVEs exploited), not exclusively to CVE-2018-8007 exploitation — treat as a shared campaign indicator rather than a CVE-2018-8007-specific IOC ↗
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv7.2HIGH
vulncheck7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mqj2-xj98-r5xp: Apache CouchDB administrative users can configure the database server via HTTP(S)
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2018-8007 [HIGH] CWE-20 GHSA-mqj2-xj98-r5xp: Apache CouchDB administrative users can configure the database server via HTTP(S)
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.
GHSA
GHSA-33mm-q6vp-mvmv: CouchDB administrative users before 2
ghsa_unreviewed·2022-05-13·CVSS 7.2
CVE-2018-11769 [HIGH] GHSA-33mm-q6vp-mvmv: CouchDB administrative users before 2
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing CVE-2017-12636 and CVE-2018-8007.
OSV
CVE-2018-11769: CouchDB administrative users before 2
osv·2018-08-08·CVSS 7.2
CVE-2018-11769 [HIGH] CVE-2018-11769: CouchDB administrative users before 2
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing CVE-2017-12636 and CVE-2018-8007.
OSV
CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S)
osv·2018-07-11·CVSS 7.2
CVE-2018-8007 [HIGH] CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S)
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.
VulnCheck
Apache CouchDB Improper Input Validation
vulncheck·2018·CVSS 7.2
CVE-2018-8007 [HIGH] Apache CouchDB Improper Input Validation
Apache CouchDB Improper Input Validation
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.
Affected: Apache CouchDB
Required Action: Apply remediations or mitigations per vendor instru
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11769 couchdb: Possible privilege escalation by couchdb administrator to system couchdb user
bugzilla·2018-12-18·CVSS 7.2
CVE-2018-11769 [HIGH] CVE-2018-11769 couchdb: Possible privilege escalation by couchdb administrator to system couchdb user
CVE-2018-11769 couchdb: Possible privilege escalation by couchdb administrator to system couchdb user
CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system’s user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API.
This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing mitigations for CVE-2017-12636 and CVE-2018-8007.
References:
https://lists.apache.org/thread.html/1052ad7a1b32b9756df4f7860f5cb5a96b739f444117325a19a4bf7
Bugzilla
CVE-2018-8007 couchdb: Administrative Privilege Escalation [fedora-all]
bugzilla·2018-07-13·CVSS 7.2
CVE-2018-8007 [HIGH] CVE-2018-8007 couchdb: Administrative Privilege Escalation [fedora-all]
CVE-2018-8007 couchdb: Administrative Privilege Escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2018-8007 couchdb: Administrative Privilege Escalation
bugzilla·2018-07-13·CVSS 7.2
CVE-2018-8007 [HIGH] CVE-2018-8007 couchdb: Administrative Privilege Escalation
CVE-2018-8007 couchdb: Administrative Privilege Escalation
CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system’s user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API.
References:
https://blog.couchdb.org/2018/07/10/cve-2018-8007/
http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3C1699016538.6219.1531246785603.JavaMail.Joan%40RITA%3E
http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3C1439409216.6221.1531246856676.JavaMail.Joan@RITA%3E
Hackernews
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
blogs_hackernews·2026-06-30·CVSS 8.8
CVE-2017-17215 [HIGH] RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.
Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.
The end goal is a distributed denial-of-service (DDoS) attack: flooding a target with junk traffic from the infected machines until it buckles.
RustDuck is one more entrant in a crowded field, b
http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3C1699016538.6219.1531246785603.JavaMail.Joan%40RITA%3Ehttp://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3c1439409216.6221.1531246856676.JavaMail.Joan%40RITA%3ehttp://www.securityfocus.com/bid/104741https://blog.couchdb.org/2018/07/10/cve-2018-8007/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S5FPHVVU5KMRFKQTJPAM3TBGC7LKCWQS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3JOUCX7LHDV4YWZDQNXT5NTKKRANZQW/https://security.gentoo.org/glsa/201812-06https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03935en_ushttps://www.mdsec.co.uk/2018/08/advisory-cve-2018-8007-apache-couchdb-remote-code-execution/http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3C1699016538.6219.1531246785603.JavaMail.Joan%40RITA%3Ehttp://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3c1439409216.6221.1531246856676.JavaMail.Joan%40RITA%3ehttp://www.securityfocus.com/bid/104741https://blog.couchdb.org/2018/07/10/cve-2018-8007/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S5FPHVVU5KMRFKQTJPAM3TBGC7LKCWQS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3JOUCX7LHDV4YWZDQNXT5NTKKRANZQW/https://security.gentoo.org/glsa/201812-06https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03935en_ushttps://www.mdsec.co.uk/2018/08/advisory-cve-2018-8007-apache-couchdb-remote-code-execution/
2018-07-11
Published
Exploited in the wild