CVE-2022-24706 - CVE House
Back to Database
Status published Unknown CVE-2022-24706

Remote Code Execution Vulnerability in Packaging

Vulnerability Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24706

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The Apache CouchDB Team would like to thank Alex Vandiver <alexmv@zulip.com> for the report of this issue.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache CouchDB
Vulnerable Versions:
Apache CouchDB

Timeline

Official Publish: April 26th, 2022
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.