LWN.net Logo

couchdb: cross-site request forgery

Package(s):couchdb CVE #(s):CVE-2010-2234
Created:September 21, 2010 Updated:September 22, 2010
Description: From the Red Hat bugzilla:

Apache CouchDB prior to 0.11.2 and 1.0.1 are vulnerable to cross site request forgery (CSRF) attacks. A malicious web site can POST arbitrary JavaScript code to wellknown CouchDB installation URLs and make the browser execute the injected JavaScript in the security context of CouchDB's admin interface Futon.

Alerts:
Fedora FEDORA-2010-13665 2010-08-27
Fedora FEDORA-2010-13640 2010-08-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds