PT-2014-2350 · Apache · Apache Couchdb

Frederik Braun

·

Publicado

2014-03-18

·

Atualizado

2014-05-31

·

CVE-2012-5650

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache CouchDB versions prior to 1.0.4 Apache CouchDB versions 1.1.x prior to 1.1.2 Apache CouchDB versions 1.2.x prior to 1.2.1
Description A cross-site scripting (XSS) issue exists in the Futon UI of Apache CouchDB, allowing remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later. For versions 1.1.x prior to 1.1.2, update to version 1.1.2 or later. For versions 1.2.x prior to 1.2.1, update to version 1.2.1 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5650

Produtos afetados

Apache Couchdb