CVE-2024-41888

MEDIUM

Apache Answer <= 1.3.5 - Missing Release of Resource after Effective Lifetime

Title source: llm
STIX 2.1

Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0122
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-772
Status published
Products (2)
apache/answer < 1.3.6
apache/incubator-answer 0 - 1.3.6Go
Published Aug 12, 2024
Tracked Since Feb 18, 2026