CVE-2017-12635

CRITICALNVD 9.89.8—
EchelonGraph scoreMEDIUM confidence

Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-13. NVD baseline CVSS 9.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
Weaponized
9.8EG
EchelonGraph verdictPatch this weekExploitation is likely or a public exploit exists.
  • High exploitation likelihood — EPSS 100%
  • Public exploit code is available (Metasploit, Exploit-DB (verified), epss top5pct, epss high, public exploit)
CISA-KEV: Not listedEPSS PROB: 100%CVSS: 9.8Exploit: Metasploit · Exploit-DB (verified) · epss top5pct · epss high · public exploitExposed services: Not assessed

A fix is available — apply it.

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.

CVSS v3
9.8
EG Score
9.8CRITICALmedium confidence
EG Risk
89
EG Risk 89/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity98% × 45%
Exploitation100% × 40%
Automatability30% × 15%
CISA SSVC: Track at low, Track* at medium and Attend at high mission impact.
Action: A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
EPSS PROB
100%
EPSS %ILE
99th
KEV
Not listed

CISA SSVCTrack at low, Track* at medium and Attend at high mission impact.

A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.

Exploitation public PoC (EG-KEV: weaponized) · Automatable unknown (not published for this CVE) · Technical impact total (CVSS ≥ 9.0). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

November 14, 2017

Last Modified

June 17, 2026

Advisory Details (7)

Auto-updated Oct 6, 2026
Patch available.
genericMentions a patch (unverified)

[SECURITY] [DLA 1252-1] couchdb security update

https://lists.debian.org/debian-lts-announce/2018/01/msg00026.html
generic

CVE-2017-12635 - PSIRT.COM

http://www.securityfocus.com/bid/101868
generic

CouchDB: Multiple vulnerabilities (GLSA 201711-16) — Gentoo security

https://security.gentoo.org/glsa/201711-16
generic🟡 PoC Available

Apache CouchDB - Arbitrary Command Execution (Metasploit) - Linux remote Exploit

https://www.exploit-db.com/exploits/45019/
generic🟡 PoC Available

Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation - Linux webapps Exploit

https://www.exploit-db.com/exploits/44498/

Affected Packages

(1 across 1 ecosystem)
Debian:7(1)
PackageVulnerable rangeFix by version rangeDependents
couchdb1.2.0-5
  • every version up to 1.2.0-5+deb7u1: fixed in 1.2.0-5+deb7u1
—

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 0× in last 7d / 6× in last 30d)

Each row is a time one of our pipelines fetched, updated or re-scored this CVE. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. An arrow marks a change the record states ("CVSS v3 → 9.1"); EPSS and GHSA rows show the values recorded at that time, not what changed (EPSS values are rounded; hover one for the exact figures). Most recent first.

A repeat, a row identical to one the same pipeline wrote less than 10 seconds earlier, is not a separate refresh and is not counted. 7 repeat rows among the latest 48 are merged into the row they repeat.

  1. 2026-10-04 02:14 UTCOSV refresh
  2. 2026-09-30 09:24 UTCEG score recompute
  3. 2026-09-24 13:59 UTCEPSS rescoreEPSS 100% · 99th percentile
  4. 2026-09-17 19:22 UTCEPSS rescoreEPSS 100% · 99th percentile
  5. 2026-09-15 03:05 UTCEPSS rescoreEPSS 100% · 99th percentile
  6. 2026-09-14 16:14 UTCOSV refresh
  7. 2026-08-30 19:13 UTCEPSS rescoreEPSS 100% · 99th percentile
  8. 2026-08-28 21:36 UTCEPSS rescoreEPSS 100% · 99th percentile
  9. 2026-08-26 16:13 UTCOSV refresh
  10. 2026-08-24 14:10 UTCEPSS rescoreEPSS 100% · 99th percentile
  11. 2026-08-16 02:10 UTCEPSS rescoreEPSS 100% · 99th percentile
  12. 2026-08-10 06:09 UTCOSV refresh
  13. 2026-08-09 13:42 UTCEPSS rescoreEPSS 100% · 99th percentile
  14. 2026-07-26 14:51 UTCEPSS rescoreEPSS 100% · 99th percentile
  15. 2026-07-25 06:41 UTCOSV refresh
  16. 2026-07-23 01:26 UTCEG score recompute
  17. 2026-07-22 22:05 UTCEG score recompute
  18. 2026-07-09 19:06 UTCEPSS rescoreEPSS 100% · 99th percentile
  19. 2026-07-08 01:05 UTCOSV refresh
  20. 2026-06-23 21:30 UTCEPSS rescoreEPSS 100% · 99th percentile
  21. 2026-06-19 12:55 UTCOSV refresh
  22. 2026-06-15 17:45 UTCEPSS rescoreEPSS 100% · 99th percentile
  23. 2026-06-12 23:09 UTCEPSS rescoreEPSS 94% · 99th percentile
  24. 2026-06-11 13:57 UTCEPSS rescoreEPSS 94% · 99th percentile
  25. 2026-06-10 22:15 UTCEPSS rescoreEPSS 94% · 99th percentile
Show 16 more
  1. 2026-06-07 15:22 UTCEPSS rescoreEPSS 94% · 99th percentile
  2. 2026-06-02 20:11 UTCEPSS rescoreEPSS 94% · 99th percentile
  3. 2026-06-01 13:49 UTCEPSS rescoreEPSS 94% · 99th percentile
  4. 2026-05-30 20:53 UTCOSV refresh
  5. 2026-05-26 07:17 UTCEPSS rescoreEPSS 94% · 99th percentile
  6. 2026-05-22 21:15 UTCEPSS rescoreEPSS 94% · 99th percentile
  7. 2026-05-20 08:23 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  8. 2026-05-20 04:14 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  9. 2026-05-20 00:05 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  10. 2026-05-19 19:56 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  11. 2026-05-19 15:47 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  12. 2026-05-19 11:37 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  13. 2026-05-19 07:24 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  14. 2026-05-19 03:10 UTCGHSA enrichmentGHSA-f3p2-qqmm-jg8f · GitHub severity CRITICAL · GitHub CVSS 9.8
  15. 2026-05-18 23:01 UTCEG score recompute
  16. 2026-05-18 21:30 UTCEPSS rescoreEPSS 94% · 99th percentile

Publicly available exploits

(6 references)

Public exploit code is referenced for this CVE (2 Metasploit modules, 2 Exploit-DB entries, 1 GitHub PoC), as is 1 Nuclei detection template. A detection template checks whether a system is affected; it is not necessarily exploit code. Defenders should treat patch urgency accordingly.

  • Exploit-DBEDB-45019✓ verified
    Published Jul 13, 2018

    Apache CouchDB - Arbitrary Command Execution (Metasploit)

    Open source ↗
  • Metasploitexploit/linux/http/apache_couchdb_cmd_exec✓ verified
    Published Jul 12, 2018

    Apache CouchDB Arbitrary Command Execution

    Open source ↗
  • Metasploitauxiliary/scanner/couchdb/couchdb_enum✓ verified
    Published May 14, 2013

    CouchDB Enum Utility

    Open source ↗
  • Nucleihttp/cves/2017/CVE-2017-12635.yaml
    Published Feb 15, 2021

    Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

    Open source ↗
  • GitHub PoCassalielmehdi/CVE-2017-12635
    Published Nov 7, 2019

    Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

    Open source ↗
  • Exploit-DBEDB-44498
    Published Apr 23, 2018

    Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

    Open source ↗

Frequently asked(5)

What is CVE-2017-12635?
CVE-2017-12635 is a critical vulnerability published on November 14, 2017. Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit users documents with duplicate keys for 'roles' used for access control within the database, including the special case 'admin' role,…
When was the CVE record for CVE-2017-12635 published?
The CVE record for CVE-2017-12635 was published on November 14, 2017. That is the record's publication date; the vulnerability itself may have been made public earlier. EchelonGraph's copy of the record carries a last-modified date of June 17, 2026; the record at its source may have been updated since.
Is CVE-2017-12635 actively exploited?
CVE-2017-12635 is not currently on CISA's Known Exploited Vulnerabilities catalog. EchelonGraph's EG-KEV model classifies it as weaponized: a functional public exploit exists. FIRST EPSS estimates a 100% probability of exploitation in the next 30 days (99th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2017-12635?
CVE-2017-12635 has a CVSS v3 base score of 9.8 (NVD).
How do I remediate CVE-2017-12635?
A fix for CVE-2017-12635 is available: update to the fixed version the vendor names in its advisory.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-12635

Explore →

Is Your Infrastructure Affected by CVE-2017-12635?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.