CVE-2012-5641
Apache CouchDB 1.0.3 / 1.1.1 / 1.2.0 Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.
Vulnerabilidad de salto de directorio en la función partition2 en mochiweb_util.erl en MochiWeb anterior a 2.4.0, utilizado en Apache CouchDB anterior a 1.0.4, 1.1.x anterior a 1.1.2 y 1.2.x anterior a 1.2.1, permite a atacantes remotos leer archivos arbitrarios a través de un ..\ (punto punto barra invertida) en la URI por defecto.
Apache CouchDB versions up to and including 1.0.3, 1.1.1, and 1.2.0 are vulnerable to an information disclosure vulnerability via unescaped backslashes in URLs on Windows.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2013-01-14 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-06-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2013/Jan/81 | Mailing List |
|
http://secunia.com/advisories/51765 | Third Party Advisory | |
http://www.securityfocus.com/bid/57313 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/81240 | Vdb Entry | |
https://github.com/mochi/mochiweb/issues/92 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://github.com/melkote/mochiweb/commit/ac2bf | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | <= 1.0.3 Search vendor "Apache" for product "Couchdb" and version " <= 1.0.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.0.0 Search vendor "Apache" for product "Couchdb" and version "1.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.0.1 Search vendor "Apache" for product "Couchdb" and version "1.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.0.2 Search vendor "Apache" for product "Couchdb" and version "1.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.1.0 Search vendor "Apache" for product "Couchdb" and version "1.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.1.1 Search vendor "Apache" for product "Couchdb" and version "1.1.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Couchdb Search vendor "Apache" for product "Couchdb" | 1.2.0 Search vendor "Apache" for product "Couchdb" and version "1.2.0" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | <= 2.3.2 Search vendor "Mochiweb Project" for product "Mochiweb" and version " <= 2.3.2" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | 2.1.0 Search vendor "Mochiweb Project" for product "Mochiweb" and version "2.1.0" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | 2.2.0 Search vendor "Mochiweb Project" for product "Mochiweb" and version "2.2.0" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | 2.2.1 Search vendor "Mochiweb Project" for product "Mochiweb" and version "2.2.1" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | 2.3.0 Search vendor "Mochiweb Project" for product "Mochiweb" and version "2.3.0" | - |
Affected
| ||||||
Mochiweb Project Search vendor "Mochiweb Project" | Mochiweb Search vendor "Mochiweb Project" for product "Mochiweb" | 2.3.1 Search vendor "Mochiweb Project" for product "Mochiweb" and version "2.3.1" | - |
Affected
|