Impact
The vulnerability is an improper authorization flaw that allows any authenticated user to reject arbitrary pending edit revisions in Apache Answer. The missing check on the reject operation means users with basic credentials can remove edit proposals without the required review permission, effectively bypassing the intended content approval workflow. This could lead to tacit removal or loss of user‑generated content and disrupt collaborative editing processes.
Affected Systems
Apache Answer products from the Apache Software Foundation are affected through version 2.0.1. All deployments running any 2.0.1 or earlier release are vulnerable unless they have applied the 2.0.2 patch. No other vendors or versions are reported to be impacted.
Risk and Exploitability
The exploit requires only that the attacker be an authenticated user with access to the application. No additional system privileges or network conditions are needed, and there is no publicly documented attack code. The vulnerability is not listed in the CISA KEV catalog and no EPSS value is available, implying a lower likelihood of widespread exploitation, yet the impact is significant for organizations relying on the edit approval process. Because the flaw is an authorization bypass, it should be considered high risk for settings where unauthorized changes are unacceptable.
OpenCVE Enrichment