VYPR

Answer

by Apache

Source repositories

CVEs (24)

  • CVE-2024-41890MedAug 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the…

  • CVE-2024-41888MedAug 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being…

  • CVE-2023-49619LowJan 10, 2024
    risk 0.20cvss 3.1epss 0.01

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number…

  • CVE-2024-45719LowNov 22, 2024
    risk 0.17cvss 2.6epss 0.00

    Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to…

Page 2 of 2