CVE-CVE-2017-12635
Severity
UNKNOWN
CVSS Score
0.0
Description
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database s...
PoCs for CVE-CVE-2017-12635
couchdb-exploit
RCE
Python
0
Darabium
2026-08-03