← Vulnerability feed

Vulnerability record · CVE-2021-38295 · published 14 October 2021

CVE-2021-38295: Apache couchdb cross-site scripting vulnerability

Apache · Couchdb

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2

7.3 CVSS 3.1 High EPSS 2.5% · top 15.8% CWE-79 · Cross-site scripting
7.3CVSS 3.1 base score, v2 6.0
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-24706Apache CouchDB default install allows unauthenticated admin accessApache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installat…KEVEPSS 93%analysed9.8CVE-2020-1955Apache couchdb missing authentication for critical function vulnerabilityCouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…EPSS 1.8%9.8CVE-2017-12635Apache CouchDB privilege escalation via duplicate JSON roles keysApache CouchDB before 1.7.0 and 2.x before 2.1.1 parses JSON differently in its Erlang and JavaScript layers, so a _users document containing duplica…EPSS 100%analysed7.8CVE-2018-14889Apache couchdb improper input validation vulnerabilityCouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.EPSS 0.56%7.8CVE-2016-8742Apache couchdb permissions and access controls vulnerabilityThe Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…EPSS 2.0%7.2CVE-2018-17188Apache couchdb vulnerabilityPrior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilit…EPSS 3.2%7.2CVE-2018-11769Apache couchdb vulnerabilityCouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied con…EPSS 8.2%7.2CVE-2018-8007Apache couchdb improper input validation vulnerabilityApache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2021-38295), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.