Dear Neighbourhoodie Customer (current or former) or Newsletter subscriber,
You are receiving this email because the just released CouchDB 3.3.3 includes a fix for CVE-2023-45725. The exact details of this vulnerability are going to be released in seven days.
As Neighbourhoodie customers, you benefit from our assessment prior to the release. In general, we recommend everyone upgrade to the latest version, but this detailed assessment helps you to decide how urgent this upgrade is for you.
Without going into any details, the two prerequisites for this vulnerability to work are:
This is a rare circumstance and while we do not want to downplay the possibility of this issue being exploited, we believe its severity is very low.
If you have any questions or feedback about any of this and you are under a Neighbourhoodie CouchDB Support contract, you can always get in touch at couchdb@neighbourhood.ie.
If you are interested in signing up for a Neighbourhoodie CouchDB Support contract, contact sales@neighbourhood.ie.
Best
Your Neighbourhoodie CouchDB Team
—