Apache CouchDB versions prior to version 0.11.0 are vulnerable to timing attacks, also known as side-channel information leakage, due to using simple break-on-inequality string comparisons when verifying hashes and passwords.
bbe4edeb361a96c9e551e286e2cd996324760c3fa8fc5cad42081d50e8efd871