漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing setting `require_valid_user`, which in turn requires that any and all requests to CouchDB will have to be made with valid credentials, effectively forbidding any anonymous requests. The new `require_valid_user_except_for_up` is an off-by-default setting that was meant to allow requiring valid credentials for all endpoints except for the `/_up` endpoint. However, the implementation of this made an error that lead to not enforcing credentials on any endpoint, when enabled. CouchDB versions 3.0.1[1] and 3.1.0[2] fix this issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache CouchDB 安全漏洞
Vulnerability Description
Apache CouchDB是美国阿帕奇(Apache)软件基金会的使用Erlang开发的一套面向文档的数据库系统。 Apache CouchDB 3.0.0版本(带有用于管理访问控制的新配置设置)中存在安全漏洞。远程攻击者可利用该漏洞提升权限。
CVSS Information
N/A
Vulnerability Type
N/A