PT-2024-13768 · Apache · Apache Answer

·

CVE-2023-49619

·

Published

2024-01-10

·

Updated

2025-06-11

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Answer versions through 1.2.0
Description The issue is related to a 'Race Condition' vulnerability due to improper synchronization when using shared resources. Normally, a user can only bookmark a question once, increasing the bookmark count by one. However, through repeated submissions using scripts, the number of question collections can be increased multiple times.
Recommendations For versions through 1.2.0, upgrade to version 1.2.1, which fixes the issue. As a temporary workaround, consider restricting the ability to submit bookmarks repeatedly to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49619
GHSA-F899-4MR4-FQPV
GO-2024-2457

Affected Products

Apache Answer