Description
Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
Affected products
- apache / couchdb0.8.0 – 0.8.0
- apache / couchdb0.8.1 – 0.8.1
- apache / couchdb0.9.0 – 0.9.0
- apache / couchdb0.9.1 – 0.9.1
- apache / couchdb0.9.2 – 0.9.2
- apache / couchdb0.10.0 – 0.10.0
- apache / couchdb0.10.1 – 0.10.1
- apache / couchdb0.11.0 – 0.11.0