PT-2026-68192 · Apache · Apache Answer
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Answer versions prior to 2.0.2
Description
Unauthorized users can retrieve the content of deleted or pending answers through the single-answer read path, provided the parent question remains visible. This leads to the exposure of sensitive information that should be inaccessible.
Recommendations
Upgrade to version 2.0.2.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Answer