{"id":"UBUNTU-CVE-2021-38295","details":"In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2","modified":"2025-10-24T04:50:28Z","published":"2021-10-14T20:15:00Z","upstream":["CVE-2021-38295"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-38295"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-38295"}],"affected":[{"package":{"name":"couchdb","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/couchdb@1.6.0-0ubuntu7?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.6.0-0ubuntu7"],"ecosystem_specific":{"binaries":[{"binary_name":"couchdb","binary_version":"1.6.0-0ubuntu7"},{"binary_name":"couchdb-bin","binary_version":"1.6.0-0ubuntu7"},{"binary_name":"couchdb-common","binary_version":"1.6.0-0ubuntu7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38295.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}