https://seclists.org/oss-sec/2024/q3/270: CVE-2024-40761: Apache Answer: Avatar URL leaked user email addsses
Published Sep 25, 2024
·Updated
Affected Software
1 affected component
Apache Answer<1.3.5
Frequently Asked Questions
1
What is the severity of CVE-2024-40761?
The severity of CVE-2024-40761 is classified as low.
2
Which versions of Apache Answer are affected by CVE-2024-40761?
CVE-2024-40761 affects all versions of Apache Answer through 1.3.5.
3
How does CVE-2024-40761 expose user email addresses?
CVE-2024-40761 exposes user email addresses by using the MD5 value of the email to access Gravatar, which is insecure.
4
How do I fix CVE-2024-40761?
To fix CVE-2024-40761, upgrade Apache Answer to a version beyond 1.3.5 that addresses this vulnerability.
5
What are the potential risks associated with CVE-2024-40761?
The potential risks associated with CVE-2024-40761 include the unauthorized leakage of user email addresses.