Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity: important
Affected versions:
- Apache Answer through 2.0.1
Description:
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Credit:
tonghuaroot (reporter) Mattia Campanelli (reporter) Cavan Loughran (reporter) Xi Yang (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-50749
Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity: important
Affected versions:
- Apache Answer through 2.0.0
Description:
Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Credit:
Sho Odagiri (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-25700
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity: important
Affected versions:
- Apache Answer through 2.0.0
Description:
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Credit:
Sho Odagiri (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-25699
Severity: important
Affected versions:
- Apache Answer through 2.0.0
Description:
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Credit:
Andy Gill, ZephrSec Ltd (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-33582
Severity: important
Affected versions:
- Apache Answer through 2.0.0
Description:
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Credit:
Reimar Fritz (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-34033
Severity: moderate
Affected versions:
- Apache Answer through 2.0.0
Description:
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Credit:
Hamed Kohi (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-34905
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.7.1.
An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
Severity: important
Affected versions:
- Apache Answer through 1.7.1
Description:
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.7.1.
An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
Credit:
Sho Odagiri of GMO Cybersecurity by Ierae, Inc. (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-24735
On 3/31/25 21:44, Enxin Xie wrote: [...]
Description:
Private Data Structure Returned From A Public Method vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.2.
If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed. This hits two major pet peeves of mine:
-- Jacob
Private Data Structure Returned From A Public Method vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.2.
If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Severity: low
Affected versions:
- Apache Answer through 1.4.2
Description:
Private Data Structure Returned From A Public Method vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.2.
If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Credit:
Hamed Kohi (reporter) Luke Smith (reporter)
References:
https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2025-29868
Severity: important
Affected versions:
- Apache Answer through 1.4.0
Description:
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.0.
The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.
Credit:
Chi Tran from Eevee (reporter)
References:
https://answer.incubator.apache.org https://www.cve.org/CVERecord?id=CVE-2024-45719
I don't think that a seeded PRF (with a per-server seed) would meet the requirements here. Now, this leaves me with a few observations:
1. The 'should be taken' from Gravatar's documentation should be 'must be taken' to ensure consistent user hashes (therefore using MD5 in the first place rendered Gravatar useless if Gravatar doesn't match against MD5 hashes as well). 2. The information leakage with Gravatar is in-spec. Fixing the information leakage would be possible but requires changes on Gravatar's side by implementing a symmetric cipher instead of a hash (as suggested; a hash wouldn't be tractable any more because Gravatar would need to hash every user's email address with every registered seed when using seeded PRF). Prior hashing wouldn't even be required given that both sides - Gravatar and the site itself - have access to the user's email address anyway. 3. It may be advisable to not use Gravatar as the default (not sure if this is the case here). Instead, let user's choose it and let them know about the potential information leakage. 4. The fix does not fix what it tries to fix. 5. Assigning a CVE for an in-spec information leakage seems not useful to me. Otherwise, every single product using Gravatar would be affected by this.
M. Sc. Fabian Bäumer
Chair for Network and Data Security Ruhr University Bochum Universitätsstr. 150, Building MC 4/145 44780 Bochum Germany
Am 27.09.2024 um 14:25 schrieb Alexander Patrakov: On Thu, Sep 26, 2024 at 5:19 AM Demi Marie Obenour <demi () invisiblethingslab com> wrote: On Wed, Sep 25, 2024 at 06:28:16AM +0000, Enxin Xie wrote: Severity: low
Affected versions:
- Apache Answer through 1.3.5
Description:
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Credit:
张岳熙 (reporter)
References:
https://answer.incubator.apache.org https://www.cve.org/CVERecord?id=CVE-2024-40761 What is the specific property of SHA256 required here? Email addresses have low entropy and I suspect they can be easily brute-forced, so leaking the SHA256 has is still bad. Instead, I would use a seeded PRF with a seed only known to the server, ensuring that the resulting value does not leak any information about the email. -- Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab I don't think that a seeded PRF (with a per-server seed) would meet the requirements here. The problem is that Gravatar would have no way of understanding which email is in question. Indeed, that would require storing all emails hashed with all registered server seeds.
What would work is an email hash encrypted symmetrically with a per-server key. Then Gravatar (who also knows this key) would decrypt the email hash and look up the avatar image.
Note that all of the above talks about a hypothetical improved version of Gravatar, not what we have right now.
Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email.
The official recommendation is to use SHA256 instead.
M. Sc. Fabian Bäumer
Chair for Network and Data Security Ruhr University Bochum Universitätsstr. 150, Building MC 4/145 44780 Bochum Germany
Am 25.09.24 um 08:28 schrieb Enxin Xie: Severity: low
Affected versions:
- Apache Answer through 1.3.5
Description:
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Credit:
张岳熙 (reporter)
References:
https://answer.incubator.apache.org https://www.cve.org/CVERecord?id=CVE-2024-40761
Severity: low
Affected versions:
- Apache Answer through 1.3.5
Description:
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Credit:
张岳熙 (reporter)
References:
https://answer.incubator.apache.org https://www.cve.org/CVERecord?id=CVE-2024-40761
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are recommended to upgrade to version 1.3.6, which fixes the issue.