Описание
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.
Ссылки
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.6 (исключая)
cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01354
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-772
Связанные уязвимости
CVSS3: 4.8
github
больше 1 года назад
Apache Answer: The link for resetting user password is not Single-Use
EPSS
Процентиль: 80%
0.01354
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-772