In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.
id: CVE-2022-24706
info:
name: CouchDB Erlang Distribution - Remote Command Execution
author: M
...