PT-2024-21428 · Apache · Apache Answer

Mohammad Reza Omrani

·

Published

2024-02-22

·

Updated

2025-03-20

·

CVE-2024-26578

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Answer versions through 1.2.1
Description The issue is related to a 'Race Condition' vulnerability due to improper synchronization during concurrent execution using shared resources. This can lead to the creation of multiple user accounts with the same name when users rapidly submit multiple registrations using scripts.
Recommendations For Apache Answer versions through 1.2.1, upgrade to version 1.2.5, which fixes the issue. As a temporary workaround, consider restricting rapid submissions during registration to minimize the risk of exploitation.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-26578
GHSA-9Q24-HWMC-797X
GO-2024-2580

Affected Products

Apache Answer