First published: Wed Jan 10 2024(Updated: )
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Answer | <1.2.1 | |
go/github.com/apache/incubator-answer | <1.2.1 | 1.2.1 |
<1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49619 is classified as a moderate severity vulnerability.
To mitigate CVE-2023-49619, upgrade Apache Answer to version 1.2.1 or later.
CVE-2023-49619 is a race condition vulnerability caused by improper synchronization when accessing shared resources.
CVE-2023-49619 affects all versions of Apache Answer up to and including version 1.2.0.
There are currently no known workarounds for CVE-2023-49619 aside from applying the recommended update.