← Back to CVE List
Vulnerability Intelligence Report
Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes

CVE-2023-26268

Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: * validate_doc_update * list * filter * filter views (using view functions as filters) * rewrite * update This doesn't affect map/reduce or search (Dreyfus) index functions. Users are recommended to upgrade to a version that is no longer affected by this issue (Apache CouchDB 3.3.2 or 3.2.3). Workaround: Avoid using design documents from untrusted sources which may attempt to cache or store data in the Javascript environment.

No Active Exploit Signals
CVSS Base Score
4.4
MEDIUM
Exploitability:1.3
Impact Score:2.8
EPSS Probability:1.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache CouchDB 0 <= 3.3.1 (affected)
Apache Software Foundation IBM Cloudant 0 <= 8349 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.429%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2023-02-21T08:19:47
Published2023-05-02T20:06:09
Last Updated2024-10-15T18:11:19

LINK COPIED TO CLIPBOARD