Apache CouchDB Cross-Site Scripting Vulnerability
Release date:
Updated on: 2013-01-19
Affected Systems:
Apache Group CouchDB 1.0.2
Apache Group CouchDB 1.0.1
Apache Group CouchDB 1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57321
CVE (CAN) ID: CVE-2012-5650
Apache CouchDB is a document-oriented database management system.
Apache CouchDB has the DOM-based cross-site scripting vulnerability when processing certain query parameters. Through a specially crafted webpage, attackers can execute arbitrary scripts.
<* Source: Frederik Braun
Link: https://bugzilla.redhat.com/show_bug.cgi? CVE-2012-5650
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/