Impact
The vulnerability allows an attacker to read deleted or pending answer content that should not be visible to them. This is a data confidentiality breach, classified as CWE‑200. An attacker could gain access to information intended for authorized users only, potentially exposing sensitive user contributions.
Affected Systems
Apache Answer versions through 2.0.1 are affected. The flaw resides in the single‑answer read path where the parent question remains visible, enabling the disclosure of answer content that should be hidden.
Risk and Exploitability
The EPSS score is < 1% and it is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request to the answer retrieval endpoint, which can be performed by an unauthenticated or low‑privilege user. Exploitation requires the parent question to remain visible. The flaw could be used to exfiltrate deleted or pending answers, compromising data confidentiality. The impact is significant for systems that handle sensitive Q&A content, and the risk is heightened by the lack of existing mitigation controls. The CVSS score is 7.5, indicating high severity.
OpenCVE Enrichment