CVE-2023-49619: Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.2.0.
Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times.
Users are recommended to upgrade to version [1.2.1], which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49619?
CVE-2023-49619 is classified as a moderate severity vulnerability.
How do I fix CVE-2023-49619?
To mitigate CVE-2023-49619, upgrade Apache Answer to version 1.2.1 or later.
What type of vulnerability is CVE-2023-49619?
CVE-2023-49619 is a race condition vulnerability caused by improper synchronization when accessing shared resources.
Which versions of Apache Answer are affected by CVE-2023-49619?
CVE-2023-49619 affects all versions of Apache Answer up to and including version 1.2.0.
Is there any workaround for CVE-2023-49619?
There are currently no known workarounds for CVE-2023-49619 aside from applying the recommended update.