Threadlinqs IntelligenceStart free

VulnerabilityCVE-2018-8007Published 2018-07-11

CVE-2018-8007 — Apache CouchDB

highPublic exploit1 PoC repo

As of 2024-09-16, CVE-2018-8007 is a HIGH-severity vulnerability in Apache CouchDB, CVSS v3.1 7.2, EPSS 11.6% (95.5th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2018-8007, most recently “RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation”.

CVSS v3.1
7.2/10High
EPSS
11.6%Higher than 95.5% of scored CVEs
CISA KEV
NoNot in the KEV catalog
Tracked threats
1Campaigns referencing it
Priority
9.4/10Threadlinqs triage score
Published
Updated 2024-09-16
CVSS v3.1 7.2 (HIGH) · EPSS 11.6% (higher than 95.5% of all scored CVEs) · Priority 9.4/10 · Published 2018-07-11

Last updated:

What is CVE-2018-8007?

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.

The record classifies CVE-2018-8007 under weakness class CWE-20. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs high-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 3008 days ago.

Severity and exploitation probability

CVSS v3.1 base score
7.2 — HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS (FIRST)
11.6% probability of exploitation in the next 30 days, higher than 95.5% of all scored CVEs
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
9.4/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2018-07-11, last modified 2024-09-16

Is CVE-2018-8007 being exploited?

Weaponised exploit code for CVE-2018-8007 is publicly available. 1 public proof-of-concept repository is tracked for this identifier.

Affected products and versions

How to fix CVE-2018-8007

No vendor patch reference has been recorded for CVE-2018-8007 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

Threat activity tracking CVE-2018-8007

1 tracked threat in the Threadlinqs corpus references CVE-2018-8007, either in the campaign’s CVE list or as an indicator on the campaign record.

Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.

Vendor advisory and patch

Vulnerability database entry

Mailing list and disclosure

Other references