PT-2023-29658 · Apache+1 · Apache Couchdb+1

Mike Rhodes

+3

·

Publicado

2023-12-05

·

Atualizado

2024-03-06

·

CVE-2023-45725

CVSS v3.1

5.7

Média

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache CouchDB versions prior to 3.3.3 IBM Cloudant versions prior to 8413
Description Design document functions that receive a user HTTP request object may expose authorization or session cookie headers of the user who accesses the document. These design document functions include list, show, rewrite, and update. An attacker can leak the session component using an HTML-like output, insert the session as an external resource, or store the credential in a local document with an update function. For the attack to succeed, the attacker must be able to insert the design documents into the database and then manipulate a user to access a function from that design document.
Recommendations For Apache CouchDB versions prior to 3.3.3, upgrade to version 3.3.3 or later. For IBM Cloudant versions prior to 8413, upgrade to version 8413 or later. As a temporary workaround, consider avoiding the use of design documents from untrusted sources that may attempt to access or manipulate request object headers. Restrict access to the vulnerable design document functions list, show, rewrite, and update to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-COUCHDB-2023-45725
CVE-2023-45725

Produtos afetados

Apache Couchdb
Ibm Cloudant