S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2017-12635 Scanner

CVE-2017-12635 scanner - Remote Privilege Escalation vulnerability in Apache Software Foundation Apache CouchDB

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-12635
9.8
CVSS

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache CouchDBby Apache Software Foundation
1.2.0 to 1.6.1
Updated Aug 22, 2026View on NVD →
Detail

Apache CouchDB is a database application that is developed under open-source licenses, featuring document-oriented NoSQL data storage technology. The tool is utilized mainly by web developers connecting to the server using HTTP/REST APIs, JavaScript-powered web applications, and external applications.

The CVE-2017-12635 vulnerability detected in Apache CouchDB software is a result of differences in the Erlang-based JSON parser and JavaScript-based JSON parser. This is a loophole in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 which allows the submission of _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin'role, that denotes administrative users. This vulnerability provides a chance to get non-admin users access to arbitrary shell commands on the server as the database system user.

This vulnerability, when exploited, can lead to tampering with, or even loss, of sensitive data, which can be used to carry out sophisticated attacks on businesses, organizations, and even individuals. The loophole can allow unauthorized users to manipulate sensitive information that can lead to security breaches, data loss, reputation damage, or other catastrophic consequences when full admin privileges are granted to a non-admin user.

s4e.io is a platform that provides pro features that can be employed to learn about vulnerabilities in digital assets quickly and efficiently. Using the platform, those who read this article can keep their digital assets such as databases, software, and websites secure at all times by learning about vulnerabilities, their potential impacts, and appropriate measures to take. Users can quickly determine if their digital assets are affected by Apache CouchDB vulnerabilities and protect their databases against potential attacks.

 

REFERENCES

Solution Advice

As a precautionary measure against this vulnerability, users of Apache CouchDB systems must take the necessary steps to ensure their systems are well-secured. Some measures that can help to protect against the loophole include:

  • Patching Apache CouchDB to at least version 2.1.1, if it's not yet patched.
  • Disable access to the Apache CouchDB system, except only for authorized users.
  • Actively monitor network activity to spot and respond to any abnormal system behavior.
  • Always have up-to-date security software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-12635 scanner - Remote Privilege Escalation vulnerability in Apache Software Foundation Apache CouchDB | S4E