CVE-2025-29868
- EPSS 0.41%
- Published 01.04.2025 08:15:14
- Last modified 15.04.2025 13:07:54
Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obta...
CVE-2024-45719
- EPSS 0.07%
- Published 22.11.2024 15:15:10
- Last modified 01.07.2025 20:29:14
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Us...
CVE-2024-40761
- EPSS 1.38%
- Published 25.09.2024 08:15:04
- Last modified 10.07.2025 21:31:58
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendat...
CVE-2024-41888
- EPSS 1.35%
- Published 12.08.2024 13:38:31
- Last modified 13.03.2025 20:15:22
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potenti...
CVE-2024-41890
- EPSS 0.62%
- Published 12.08.2024 13:38:31
- Last modified 13.03.2025 19:15:47
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this c...
CVE-2024-29217
- EPSS 0.21%
- Published 21.04.2024 16:15:47
- Last modified 30.06.2025 13:41:02
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their...
CVE-2024-22393
- EPSS 21.73%
- Published 22.02.2024 10:15:08
- Last modified 05.05.2025 21:00:08
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an att...
CVE-2024-23349
- EPSS 2.71%
- Published 22.02.2024 10:15:08
- Last modified 28.03.2025 20:15:21
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own subm...
CVE-2024-26578
- EPSS 0.28%
- Published 22.02.2024 10:15:08
- Last modified 20.03.2025 20:15:31
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the s...
CVE-2023-49619
- EPSS 0.98%
- Published 10.01.2024 09:15:44
- Last modified 11.06.2025 17:15:35
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and w...