Apache CouchDB before 1.7.0 and 2.x before 2.1.1 permits administrative users to configure server settings through HTTP(S), including settings that specify paths to operating-system binaries subsequently launched by CouchDB. An authenticated CouchDB administrator can abuse these binary-path configuration options to execute arbitrary shell commands in the security context of the CouchDB user, including commands that download and run scripts from the public internet.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python exploit for Apache CouchDB targeting CVE-2017-12635 and CVE-2017-12636. It contains three files: a README with usage/examples, a requirements file, and a single executable script, couchdb-exploit.py, which is the main entry point. The exploit is not part of a larger framework. Its workflow is straightforward: it builds an HTTP base URL from a user-supplied target and port, then attempts to exploit the CouchDB duplicate-JSON-key parsing issue by sending a crafted user document to the _users database. The payload uses duplicate roles fields so that one parser sees the _admin role while another stores a benign-looking structure, resulting in creation of an administrative user with hardcoded credentials darabium / pwned@123. After creating the admin user, the script verifies success by requesting /_all_dbs with HTTP Basic Auth. If successful, it drops into an interactive shell-like interface. Based on the README and visible code, the shell supports database enumeration, viewing full database contents, showing raw responses, counting documents, searching across databases, executing arbitrary system commands, and triggering a reverse shell. The code also maintains a local command history and attempts cleanup on exit by deleting the created admin user and the temporary rce_test database. For code execution, the script uses authenticated CouchDB administrative functionality associated with CVE-2017-12636. It creates a temporary database and a malicious design document under /rce_test/_design/rce, then triggers the view endpoint /rce_test/_design/rce/_view/myview to cause command execution on the host. The reverse-shell feature appears to construct a shell command using attacker-supplied IP and port and then trigger it through the same design-document/view mechanism. Notable observables include the hardcoded credentials, the temporary database name rce_test, and the design document/view path used for execution. The exploit is operational rather than a mere proof of concept because it includes end-to-end exploitation logic and post-exploitation capabilities, but it is still relatively basic and hardcoded rather than highly modular or framework-driven.
This repository contains a single Metasploit module (modules/exploits/linux/http/apache_couchdb_cmd_exec.rb) that exploits two vulnerabilities (CVE-2017-12635 and CVE-2017-12636) in Apache CouchDB versions prior to 1.7.0 and 2.x prior to 2.1.1. The exploit targets the HTTP(S) administrative interface of CouchDB, abusing JSON parser inconsistencies and query server configuration to achieve arbitrary command execution as the CouchDB user. The module supports both authentication bypass (via crafted JSON) and authenticated exploitation, and delivers payloads using Metasploit's command stager (curl/wget) to a writable directory (default: /tmp). The default payload is a reverse shell, but any compatible Metasploit payload can be used. The exploit is weaponized, reliable, and leverages several HTTP endpoints and file paths during exploitation. The repository is structured as a typical Metasploit module, with all logic contained in a single Ruby file.
This repository provides a proof-of-concept exploit for CVE-2017-12636, an arbitrary command execution vulnerability in Apache CouchDB 1.6.0. The repository contains three files: a README.md briefly describing the vulnerability, a docker-compose.yml for quickly deploying a vulnerable CouchDB instance, and exp.py, the main exploit script. The exploit works by first creating an admin user, then abusing CouchDB's query server configuration to inject a shell command ("id > /tmp/success"). It then triggers the execution of this command by making a request to a temporary view. The exploit demonstrates successful command execution by writing the output of 'id' to /tmp/success on the target server. The attack vector is network-based, targeting the CouchDB HTTP API. The endpoints used are all relative to the CouchDB REST interface, and the exploit is operational, providing a working demonstration of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.