CVE-2024-29217: Apache Answer: XSS vulnerability when changing personal website
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/XSS) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.
XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/apache/incubator-answerto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29217?
CVE-2024-29217 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-29217?
To mitigate CVE-2024-29217, update to Apache Answer version 1.3.0 or later.
What types of attacks are possible with CVE-2024-29217?
CVE-2024-29217 can allow attackers to execute cross-site scripting (XSS) attacks when users modify their personal websites.
Who is affected by CVE-2024-29217?
CVE-2024-29217 affects users of Apache Answer versions prior to 1.3.0.
When was CVE-2024-29217 disclosed?
CVE-2024-29217 was disclosed in 2024.