← back
CVE-2023-49619

Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.

CVSS 3.1 LOWEPSS 0.9%CWE-362
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.1EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
10 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →