CVE Database
/

CVE-2023-45725

Back to search

CVE-2023-45725

Published: Dec 13, 2023

Modified: Aug 2, 2024

PUBLISHED

Description

Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. These design document functions are: *   list *   show *   rewrite *   update An attacker can leak the session component using an HTML-like output, insert the session as an external resource (such as an image), or store the credential in a _local document with an "update" function. For the attack to succeed the attacker has to be able to insert the design documents into the database, then manipulate a user to access a function from that design document. Workaround: Avoid using design documents from untrusted sources which may attempt to access or manipulate request object's headers

VendorProductVersions

Apache Software Foundation

Apache CouchDB

affected
0 - <= 3.3.2

Apache Software Foundation

IBM Cloudant

affected
0 - < 8413

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now