CVE-2024-41890

MEDIUM

Apache Answer < 1.3.6 - Resource Leak

Title source: rule
STIX 2.1

Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

Scores

CVSS v3 5.3
EPSS 0.0062
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-772
Status published
Products (2)
apache/answer < 1.3.6
apache/incubator-answer 0 - 1.3.6Go
Published Aug 12, 2024
Tracked Since Feb 18, 2026