https://seclists.org/oss-sec/2024/q3/279: CVE-2024-40761: Apache Answer: Avatar URL leaked user email addsses
Published Sep 26, 2024
·Updated
Affected Software
1 affected component
Apache Answer<=1.3.5
Frequently Asked Questions
1
What is the severity of CVE-2024-40761?
CVE-2024-40761 is considered a high severity vulnerability due to the potential leakage of user email addresses.
2
How do I fix CVE-2024-40761?
To fix CVE-2024-40761, it is recommended to replace MD5 with SHA256 for hashing user email addresses.
3
What does CVE-2024-40761 impact?
CVE-2024-40761 impacts the Apache software by compromising user privacy through email address exposure.
4
Who reported CVE-2024-40761?
CVE-2024-40761 was reported by M. Sc. Fabian Bäumer from the Chair for Network and Data Security at Ruhr University Bochum.
5
When was CVE-2024-40761 published?
CVE-2024-40761 was published on September 26, 2024.