AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-38295

HIGH · CVSS 7.3 EPSS 2.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-10-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-38295
Severity
HIGH
CVSS
7.3
EPSS
2.47%
Apache Java

Original NVD Description

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2