CVE-2021-38295
published 2021-10-14CVE-2021-38295: In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin…
PriorityP338high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
2.47%
82.9th percentile
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | couchdb | < 3.1.2 | 3.1.2 |
| apache_software_foundation | apache_couchdb | >= Apache CouchDB < 3.1.2 | 3.1.2 |
| apache_software_foundation | ibm_cloudant | >= IBM Cloudant < 8201 | 8201 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gr7p-9mx8-wr74: In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document
ghsa_unreviewed·2022-05-24
CVE-2021-38295 [HIGH] CWE-269 GHSA-gr7p-9mx8-wr74: In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2
OSV
CVE-2021-38295: In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document
osv·2021-10-14·CVSS 7.3
CVE-2021-38295 [HIGH] CVE-2021-38295: In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2
Red Hat
couchdb: forget HTML attachment may lead to privileges escalation
vendor_redhat·2021-10-12·CVSS 7.3
CVE-2021-38295 [HIGH] CWE-345 couchdb: forget HTML attachment may lead to privileges escalation
couchdb: forget HTML attachment may lead to privileges escalation
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2
Package: camel-couchdb (Red Hat Fuse 7) - Not affected
Package: camel-couchdb (Red Hat Integration Camel K 1) - No
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-14
Published