MGASA-2022-0466

Source
https://advisories.mageia.org/MGASA-2022-0466.html
Import Source
https://advisories.mageia.org/MGASA-2022-0466.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0466
Related
Published
2022-12-17T18:48:08Z
Modified
2022-12-17T17:42:50Z
Summary
Updated couchdb packages fix security vulnerability
Details

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. (CVE-2022-24706)

References
Credits

Affected packages

Mageia:8 / couchdb

Package

Name
couchdb
Purl
pkg:rpm/mageia/couchdb?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.2-1.mga8

Ecosystem specific

{
    "section": "core"
}