Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Repeated submission during registration resulted in the registration of the same user. When users register, if they rapidly submit multiple registrations using scripts, it can result in the creation of multiple user accounts simultaneously with the same name.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Dec 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache answer |
|
CPEs | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache answer |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-02-22T09:28:15.274Z
Updated: 2024-08-02T00:07:19.622Z
Reserved: 2024-02-19T07:28:17.523Z
Link: CVE-2024-26578
Vulnrichment
Updated: 2024-07-05T15:20:40.720Z
NVD
Status : Analyzed
Published: 2024-02-22T10:15:08.503
Modified: 2024-12-11T14:25:58.393
Link: CVE-2024-26578
Redhat
No data.