CVE-2024-41888

MEDIUM

Apache Answer < 1.3.6 - Resource Leak

Title source: rule

Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

Scores

CVSS v3 5.3
EPSS 0.0135
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-772
Status published

Affected Products (2)

apache/answer < 1.3.6
apache/incubator-answer < 1.3.6Go

Timeline

Published Aug 12, 2024
Tracked Since Feb 18, 2026