CVE-2022-24706
KEVHIGH 10.0EPSS 92.5%
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 92.51% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-08-25
- Nuclei
- critical · CWE-1188
- Published
- 2022-04-26
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.ht…
- http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.h…
- Li468446/Apache_poc0★ · 2023-07-23
- becrevex/CVE-2022-247060★ · 2025-04-25
- sadshade/CVE-2022-24706-CouchDB-Exploit29★ · 2022-05-20
- superzerosec/CVE-2022-247060★ · 2022-07-04
- junghyeonkum/CVE-2022-24706
- zhongxinxuhk/Apache_poc