August 25, 2022 · Applied Cybernetics Group
CVE-2022-24706 — Apache CouchDB
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
- Added to KEV
2022-08-25- Federal due date
2022-09-15- Vendor
- Apache
- Product
- CouchDB
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-24706
CISA short description
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
Required action
Apply updates per vendor instructions.