CVE-2017-12635 is an authorization bypass vulnerability in Apache CouchDB (before 1.7.0 and 2.x before 2.1.1) caused by differences between the Erlang-based JSON parser and the JavaScript-based JSON parser used for document validation. Specifically, when a _users document is submitted with duplicate 'roles' keys, the two parsers interpret which value to use differently: the second 'roles' key is used for authorizing the document write, but the first is used for subsequent authorization. This allows non-admin users to create accounts with admin privileges, bypassing intended access controls. In combination with CVE-2017-12636, this can lead to remote code execution as the database system user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository is a small standalone Python exploit for Apache CouchDB targeting CVE-2017-12635 and CVE-2017-12636. It contains three files: a README with usage/examples, a requirements file, and a single executable script, couchdb-exploit.py, which is the main entry point. The exploit is not part of a larger framework. Its workflow is straightforward: it builds an HTTP base URL from a user-supplied target and port, then attempts to exploit the CouchDB duplicate-JSON-key parsing issue by sending a crafted user document to the _users database. The payload uses duplicate roles fields so that one parser sees the _admin role while another stores a benign-looking structure, resulting in creation of an administrative user with hardcoded credentials darabium / pwned@123. After creating the admin user, the script verifies success by requesting /_all_dbs with HTTP Basic Auth. If successful, it drops into an interactive shell-like interface. Based on the README and visible code, the shell supports database enumeration, viewing full database contents, showing raw responses, counting documents, searching across databases, executing arbitrary system commands, and triggering a reverse shell. The code also maintains a local command history and attempts cleanup on exit by deleting the created admin user and the temporary rce_test database. For code execution, the script uses authenticated CouchDB administrative functionality associated with CVE-2017-12636. It creates a temporary database and a malicious design document under /rce_test/_design/rce, then triggers the view endpoint /rce_test/_design/rce/_view/myview to cause command execution on the host. The reverse-shell feature appears to construct a shell command using attacker-supplied IP and port and then trigger it through the same design-document/view mechanism. Notable observables include the hardcoded credentials, the temporary database name rce_test, and the design document/view path used for execution. The exploit is operational rather than a mere proof of concept because it includes end-to-end exploitation logic and post-exploitation capabilities, but it is still relatively basic and hardcoded rather than highly modular or framework-driven.
This repository contains a single Metasploit module (modules/exploits/linux/http/apache_couchdb_cmd_exec.rb) that exploits two vulnerabilities (CVE-2017-12635 and CVE-2017-12636) in Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1. The exploit targets the HTTP(S) administrative interface of CouchDB, abusing JSON parser inconsistencies and query server configuration to achieve arbitrary command execution as the CouchDB user. The module supports both authentication bypass (via crafted JSON) and authenticated exploitation, and delivers payloads using Metasploit's command stager (curl/wget) to a writable directory (default: /tmp). The default payload is a reverse shell, but any compatible Metasploit payload can be used. The exploit is weaponized, reliable, and leverages several HTTP endpoints and file paths during exploitation. The repository is structured as a typical Metasploit module, with all logic contained in a single Ruby file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.