https://seclists.org/oss-sec/2024/q4/111: CVE-2024-45719: Apache Answer: Pdictable Authorization Token Using UUIDv1
Published Nov 22, 2024
·Updated
Affected Software
1 affected component
Apache Answer<1.4.0
Frequently Asked Questions
1
What is the severity of CVE-2024-45719?
The severity of CVE-2024-45719 is marked as important.
2
Which versions of Apache Answer are affected by CVE-2024-45719?
Apache Answer versions through 1.4.0 are affected by CVE-2024-45719.
3
What type of vulnerability is CVE-2024-45719?
CVE-2024-45719 is classified as an Inadequate Encryption Strength vulnerability.
4
What is the primary issue introduced by CVE-2024-45719?
CVE-2024-45719 introduces security concerns due to the use of UUIDv1 for token generation, which is not secure enough.
5
How can I mitigate the risks associated with CVE-2024-45719?
To mitigate the risks of CVE-2024-45719, consider upgrading to a secure version of Apache Answer beyond 1.4.0.