Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.
History

Thu, 29 Aug 2024 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache answer
CPEs cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache answer
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 09 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
References

Fri, 09 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
Description Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.
Title Apache Answer: The link for resetting user password is not Single-Use
Weaknesses CWE-772
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-08-09T14:55:14.493Z

Updated: 2024-08-09T15:17:00.862Z

Reserved: 2024-07-23T02:21:14.245Z

Link: CVE-2024-41888

cve-icon Vulnrichment

Updated: 2024-08-09T15:02:53.375Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:31.617

Modified: 2024-08-29T12:55:09.210

Link: CVE-2024-41888

cve-icon Redhat

No data.