![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2021-38295 |
Description: | In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2 |
Test IDs: | 1.3.6.1.4.1.25623.1.0.146931 1.3.6.1.4.1.25623.1.1.10.2021.0520 1.3.6.1.4.1.25623.1.0.146930 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2021-38295 https://docs.couchdb.org/en/stable/cve/2021-38295.html https://docs.couchdb.org/en/stable/cve/2021-38295.html |