SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-49619

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.

LOW 3.1EPSS 0.89%

Does this matter?

Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.

Description

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.

CVSS 3.1
3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.89% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
apache/answer
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.