CVE-2024-22393: Apache Answer: Pixel Flood Attack by uploading the large pixel file
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.
Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.
Users are recommended to upgrade to version 1.2.5, which fixes the issue.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/apache/incubator-answerto a version that resolves this vulnerability.Fixed in 1.2.5 - Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 1.2.5Patch CVE-2024-22393
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22393?
CVE-2024-22393 is categorized as a critical vulnerability due to its potential for creating an out-of-memory condition on affected servers.
How do I fix CVE-2024-22393?
To fix CVE-2024-22393, update Apache Answer to version 1.2.5 or later.
What software versions are affected by CVE-2024-22393?
CVE-2024-22393 affects Apache Answer versions prior to 1.2.1.
What types of files can be exploited in CVE-2024-22393?
CVE-2024-22393 is exploited by uploading large pixel files, which can overwhelm server memory.
Who can exploit CVE-2024-22393?
Any logged-in user can exploit CVE-2024-22393 by uploading an image to the affected Apache Answer server.