← Vulnerability feed

Vulnerability record · CVE-2012-5649 · published 23 May 2014

CVE-2012-5649: Apache couchdb code injection vulnerability

Apache · Couchdb

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

6.8 CVSS 2.0 Medium EPSS 6.6% · top 6.4% CWE-94 · Code injection
6.8CVSS 2.0 base score
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5649 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-24706Apache CouchDB default install allows unauthenticated admin accessApache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installat…KEVEPSS 93%analysed9.8CVE-2020-1955Apache couchdb missing authentication for critical function vulnerabilityCouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…EPSS 1.8%9.8CVE-2017-12635Apache CouchDB privilege escalation via duplicate JSON roles keysApache CouchDB before 1.7.0 and 2.x before 2.1.1 parses JSON differently in its Erlang and JavaScript layers, so a _users document containing duplica…EPSS 100%analysed7.8CVE-2018-14889Apache couchdb improper input validation vulnerabilityCouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.EPSS 0.56%7.8CVE-2016-8742Apache couchdb permissions and access controls vulnerabilityThe Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…EPSS 2.0%7.3CVE-2021-38295Apache couchdb cross-site scripting vulnerabilityIn Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB…EPSS 2.5%7.2CVE-2018-17188Apache couchdb vulnerabilityPrior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilit…EPSS 3.2%7.2CVE-2018-11769Apache couchdb vulnerabilityCouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied con…EPSS 8.2%

Source: NIST National Vulnerability Database (record CVE-2012-5649), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.