Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqcc-mfhw-53pc

Опубликовано: 01 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.1
CVSS3: 6.5

Описание

Apache Answer User Using External Images Potentially Discloses User Information

Private Data Structure Returned From A Public Method vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.4.2.

If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

Пакеты

Наименование

github.com/apache/answer

go
Затронутые версииВерсия исправления

< 1.4.5

1.4.5

EPSS

Процентиль: 84%
0.02242
Низкий

1.1 Low

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-495

Связанные уязвимости

CVSS3: 6.5
nvd
10 месяцев назад

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

CVSS3: 6.5
fstec
10 месяцев назад

Уязвимость Q&A-платформы Apache Answer, связанная с возвратом ссылки на защищённые данные из публичного метода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 84%
0.02242
Низкий

1.1 Low

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-495