Release: CouchDB 0.10.2, Fixing Time Attack Vulnerability
Apache CouchDB 0.10.2 has been released to fix the ☞ CVE02010-0009 Timing Attack vulnerability. This issue has also been fixed in the CouchDB 0.11.0 release and users are advised to upgrade to either of these versions, preferably to 0.11.0 which is also a feature freeze for the upcoming CouchDB 1.0.