https://seclists.org/oss-sec/2024/q1/154: CVE-2024-26578: Apache Answer: Repeated submission at registration created duplicate users with the same name
Published Feb 22, 2024
·Updated
Affected Software
1 affected component
Apache Answer<1.2.1
Frequently Asked Questions
1
What is the severity of CVE-2024-26578?
The severity of CVE-2024-26578 is classified as moderate.
2
Which versions of Apache Answer are affected by CVE-2024-26578?
Apache Answer versions through 1.2.1 are affected by CVE-2024-26578.
3
What is the nature of the vulnerability described in CVE-2024-26578?
CVE-2024-26578 is a concurrency issue caused by a race condition leading to improper synchronization during registration.
4
How do I fix CVE-2024-26578?
To fix CVE-2024-26578, you should upgrade to a patched version of Apache Answer later than 1.2.1.
5
What impact does CVE-2024-26578 have on users?
CVE-2024-26578 can result in duplicated user registrations when multiple submissions occur simultaneously.