CVE-2018-8007 describes a privilege escalation vulnerability in Apache CouchDB versions 1.x and earlier than 2.1.2. An existing CouchDB administrative user can bypass configuration setting validation via the HTTP API, allowing them to escalate privileges to the operating system user running CouchDB. This high-severity vulnerability (CVSS 7.2) enables arbitrary remote code execution, bypassing a previously disclosed RCE. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.1CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.1.1CPE matchmatch criteria | cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.