
Apache CouchDB 3.2.1 - リモートコード実行 (RCE)
日付: 2022-01-21
Exploit作成者: Konstantin Burov, @_sadshade
ソフトウェアリンク: https://couchdb.apache.org/
バージョン: 3.2.1 以下
テスト環境: Kali 2021.2
1F98D氏のErlang Cookie - リモートコード実行に基づく
Shodan: port:4369 "name couchdb at"
CVE: CVE-2022-24706
参考文献:
https://habr.com/ru/post/661195/
https://www.exploit-db.com/exploits/49418
https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/