Medium severity5.3NVD Advisory· Published Sep 25, 2024· Updated Jun 17, 2026
CVE-2024-40761
CVE-2024-40761
Description
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/incubator-answerGo | < 1.4.0 | 1.4.0 |
Affected products
3- Apache Software Foundation/Apache Answerv5Range: 0
Patches
Vulnerability mechanics
References
15- www.openwall.com/lists/oss-security/2024/09/25/2nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/25/5nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/25/6nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/25/7nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/25/8nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/26/1nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/26/3nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/26/4nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/27/4nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/27/5nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/09/27/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-48cr-j2cx-mcr8ghsaADVISORY
- lists.apache.org/thread/mmrhsfy16qwrw0pkv0p9kj40vy3sg08xnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-40761ghsaADVISORY
- github.com/apache/incubator-answer/commit/c3a17046c6c3be1cec16ba49d07d9f7742b7260fghsaWEB
News mentions
0No linked articles in our index yet.