CVE-2012-5641
Published Mar 18, 2014
Last updated 7 years ago
Overview
- Description
- Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6B47DCC-A6D4-452D-914D-2C3261022ECF", "versionEndIncluding": "1.0.3" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6572D2CB-472B-4CF0-B802-F52C12BA88BC" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F3142CB-1AF1-456D-AF66-3701FECBD490" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00AEAD55-82F4-4B18-A7DA-56B0D3EFAF3E" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3513A36D-5D92-4CDC-AA96-F3E2A390B493" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B49729E5-5B82-47AB-A9A6-5ED7C725591C" }, { "criteria": "cpe:2.3:a:apache:couchdb:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4C2436A-0E85-44F8-9691-B193D8E3B8A5" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD552EB6-A95F-4B80-B5B1-FBAB83CBCC77", "versionEndIncluding": "2.3.2" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "172A46BC-F900-4407-8968-A28D10BEFC8E" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91783915-10E5-4798-BF53-F8F14133FE86" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4150C96-780E-45F7-A7BB-4B8C9331C8F9" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:2.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BBEBF7F-68BE-48E6-AE24-F1430296D63F" }, { "criteria": "cpe:2.3:a:mochiweb_project:mochiweb:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3DD416F-E07A-480B-9D66-EE001E1AB9AC" } ], "operator": "OR" } ] } ]