Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-60053

Опубликовано: 05 авг. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Insufficient Session Expiration vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
Версия до 2.0.2 (исключая)

EPSS

Процентиль: 28%
0.00349
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.1
github
19 дней назад

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

EPSS

Процентиль: 28%
0.00349
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-613