CVE-2024-41890

MEDIUM

Apache Answer < 1.3.6 - Resource Leak

Title source: rule

Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

Scores

CVSS v3 5.3
EPSS 0.0062
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-772
Status published

Affected Products (2)

apache/answer < 1.3.6
apache/incubator-answer < 1.3.6Go

Timeline

Published Aug 12, 2024
Tracked Since Feb 18, 2026