PoC Index

CVE-2022-24706

KEVHIGH 10.0EPSS 92.5%

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
92.51% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-08-25
Nuclei
critical · CWE-1188
Published
2022-04-26
Updated
2025-10-21

Proof-of-concept exploits (8)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

Vulhub environments (1)

Exploit collections (1)

References

Related