EXPOSURES › CVE-2022-24706
CVE-2022-24706
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
Apache CouchDB default initialization flaw allows admin privilege escalation
An Apache CouchDB vulnerability enabled attackers to gain administrative access by exploiting an insecure default initialization setting, posing a high risk to DIB systems due to active exploitation in the wild.
Shame score — Active exploitation in the wild indicates negligence and a failure to apply timely security patches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.