SB20231212106 - Privilege escalation in Apache CouchDB



SB20231212106 - Privilege escalation in Apache CouchDB

Published: December 12, 2023

Security Bulletin ID SB20231212106
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: CVE-2023-45725)

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper input validation. A remote user with access to design documents can insert specially crafted HTML code into the database and gain access to authorization or session cookie headers when the victim opens the design documents.


Remediation

Install update from vendor's website.