← Back to browse · API

CVE-2022-24706

Severity
CRITICAL
CVSS
9.8
EPSS
0.92414
Risk score
57.34
CISA KEV
Yes
PoC
No
Published
2022-04-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-29572, GHSA-VXC9-8M8H-9CP6
Products
Apache Software Foundation:Apache CouchDB Apache CouchDB ≤3.2.1, Apache:CouchDB
Sources
cisa.gov CVE-2022-24706
euvd EUVD-2022-29572

Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

References