cbcvebase.
CVE-2018-8007
published 2018-07-11

CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration…

PriorityP277high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
11.68%
95.6th percentile
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachecouchdb< 2.2.02.2.0
apachecouchdb<= 1.7.1
apachecouchdb2.0.0 – 2.1.1

Detection & IOCsextracted from sources · hover to see the quote

ip176.65.139[.]204
  • ·CVE-2018-8007 exploitation requires authenticated CouchDB administrator credentials — this is a privilege escalation from admin to OS user, not an unauthenticated RCE; detections should focus on suspicious HTTP API configuration changes by admin accounts
  • ·CVE-2018-8007 was subsequently bypassed by CVE-2018-11769, which itself bypassed mitigations for both CVE-2017-12636 and CVE-2018-8007 — patching to 1.7.2/2.1.2 alone may be insufficient if CVE-2018-11769 is also applicable
  • ·The IP 176.65.139[.]204 is attributed to RustDuck botnet delivery broadly (20+ CVEs exploited), not exclusively to CVE-2018-8007 exploitation — treat as a shared campaign indicator rather than a CVE-2018-8007-specific IOC

CVSS provenance

nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv7.2HIGH
vulncheck7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.