Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in github.com/apache/incubator-answer: GHSA-v3x9-wrq5-868j #3065

Closed
GoVulnBot opened this issue Aug 12, 2024 · 1 comment
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-v3x9-wrq5-868j references a vulnerability in the following Go modules:

Module
github.com/apache/incubator-answer

Description:
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.3.5.

The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked.
Users are recommended to upgrade to version 1.3.6, which fixes the issue.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/apache/incubator-answer
      versions:
        - fixed: 1.3.6
      vulnerable_at: 1.3.6-RC1
summary: 'Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer'
cves:
    - CVE-2024-41888
ghsas:
    - GHSA-v3x9-wrq5-868j
references:
    - advisory: https://github.com/advisories/GHSA-v3x9-wrq5-868j
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-41888
    - fix: https://github.com/apache/incubator-answer/commit/2820efc454f5808974dce0aa99aac106be3f727b
    - web: https://lists.apache.org/thread/jbs1j2o9rqm5sc19jyk3jcfvkmfkmyf4
source:
    id: GHSA-v3x9-wrq5-868j
    created: 2024-08-12T19:01:14.167310545Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/605315 mentions this issue: data/reports: add 7 unreviewed reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants