Mageia 2022-0466: couchdb security update
Summary
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly
secured default installation without authenticating and gain admin
privileges. The CouchDB documentation has always made recommendations for
properly securing an installation, including recommending using a firewall
in front of all CouchDB installations. (CVE-2022-24706)
References
- https://bugs.mageia.org/show_bug.cgi?id=30342
- https://www.openwall.com/lists/oss-security/2022/04/26/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24706
Resolution
MGASA-2022-0466 - Updated couchdb packages fix security vulnerability
SRPMS
- 8/core/couchdb-3.2.2-1.mga8