https://seclists.org/oss-sec/2024/q3/185: CVE-2024-41890: Apache Answer: The link to set the user's password will main valid after sending a new link
Published Aug 9, 2024
·Updated
Affected Software
1 affected component
Apache Answer<1.3.5
Frequently Asked Questions
1
What is the severity of CVE-2024-41890?
The severity of CVE-2024-41890 is categorized as moderate.
2
Which versions are affected by CVE-2024-41890?
CVE-2024-41890 affects Apache Answer through version 1.3.5.
3
What is the main issue described in CVE-2024-41890?
CVE-2024-41890 describes a Missing Release of Resource after Effective Lifetime vulnerability.
4
How does CVE-2024-41890 affect password reset functionality?
CVE-2024-41890 enables users to send multiple password reset emails, each containing a valid link.
5
What steps can be taken to mitigate CVE-2024-41890?
To mitigate CVE-2024-41890, it is recommended to upgrade Apache Answer to a patched version above 1.3.5.