CVE-2022-24706

critical KEV
Published 2022-08-25 · Modified 2022-08-25
CVSS v3
CVSS v2
VIR risk
10.0

Description

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

CISA KEV

Vendor
Apache
Product
CouchDB
Due date
2022-09-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00; https://nvd.nist.gov/vuln/detail/CVE-2022-24706

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-24706.html

Exploits

OS impact

OSVersionStatusFixed in
arch archfixed3.2.2-2
suse slesaffected

References

Verify integrity in audit chain (admin only). AS-IS.