Логотип exploitDog
bind:CVE-2024-41888
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-41888

Количество 2

Количество 2

nvd логотип

CVE-2024-41888

больше 1 года назад

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-v3x9-wrq5-868j

больше 1 года назад

Apache Answer: The link for resetting user password is not Single-Use

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-41888

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-v3x9-wrq5-868j

Apache Answer: The link for resetting user password is not Single-Use

CVSS3: 4.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу