Skip to content
COOEY

EXPOSURES › CVE-2022-24706

CVE-2022-24706

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-24706 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Apache CouchDB default initialization flaw allows admin privilege escalation

An Apache CouchDB vulnerability enabled attackers to gain administrative access by exploiting an insecure default initialization setting, posing a high risk to DIB systems due to active exploitation in the wild.

Shame score — Active exploitation in the wild indicates negligence and a failure to apply timely security patches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.