Логотип exploitDog
bind:CVE-2024-41890
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-41890

Количество 2

Количество 2

nvd логотип

CVE-2024-41890

больше 1 года назад

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gvpv-r32v-9737

больше 1 года назад

Apache Answer: The link to reset the user's password will remain valid after sending a new link

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-41890

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-gvpv-r32v-9737

Apache Answer: The link to reset the user's password will remain valid after sending a new link

CVSS3: 4.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу