Apache CouchDB versions prior to version 0.11.0 are vulnerable to timing attacks, also known as side-channel information leakage, due to using simple break-on-inequality string comparisons when verifying hashes and passwords.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/87902/CVE-2010-0009.txt
Source: https://packetstormsecurity.com/files/87902/Apache-CouchDB-Timing-Attack.html

