CVE-2017-12635 is a critical privilege escalation vulnerability affecting Apache CouchDB versions before 1.7.0 and 2.x before 2.1.1. It arises from a JSON parser discrepancy that allows non-admin users to assign themselves administrative privileges by submitting _users documents with duplicate 'roles' keys. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-exploitable nature, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit modules are publicly available in Metasploit and Nuclei, and it has garnered significant community discussion and media coverage, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:2.0.0:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:2.0.0:rc1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:2.0.0:rc2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:2.0.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.