Number: AV17-182
Date: 5 December 2017
Purpose
The purpose of this advisory is to bring attention to the recently released critical security updates for Apache Struts and Apache CouchDB.
Assessment
Apache has released Struts 2.5.14.1 which contains security fixes to address a critical vulnerabilities in their software. Additionally, the vulnerability in Apache CouchDB could be used to give administrator level privileges to non-admin users.
Versions Affected:
- Apache Struts 2.5 to Struts 2.5.14
- Apache CouchDB before 1.7.0 and 2.x before 2.1.1
CVE References: CVE-2017-7525, CVE-2017-15707, CVE-2017-12635, CVE-2017-12636
Suggested Action
CCIRC recommends that system administrators refer to the linked security bulletin where Apache outlines the updates that remediate these vulnerabilities.
References:
https://cwiki.apache.org/confluence/display/WW/S2-054
https://cwiki.apache.org/confluence/display/WW/S2-055
https://nvd.nist.gov/vuln/detail/CVE-2017-12635
https://nvd.nist.gov/vuln/detail/CVE-2017-12636