vulnerability

FreeBSD: VID-a7dd4c2d-77e4-46de-81a2-c453c317f9de (CVE-2021-39205): couchdb -- user privilege escalation

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Oct 12, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Cory Sabol reports: A malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality.

Solution

freebsd-upgrade-package-couchdb
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.