Missing Release of Resource after Effective Lifetime in Apache Answer - CVE-2024-41888

 

Missing Release of Resource after Effective Lifetime in Apache Answer - CVE-2024-41888

Published: August 20, 2024


Vulnerability identifier: #VU96230
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41888
CWE-ID: CWE-772
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over another users' accounts.

The vulnerability exists within the password reset functionality, which does not invalidate the password reset link after it has been used to reset the password. A remote attacker can brute-force the password reset token and take over the victim's account even after the victim has successful reset their password.

Affected software

Apache Answer

How to mitigate CVE-2024-41888

Install updates from vendor's website.

Apache Answer - update to 1.3.6

External References

Related Security Bulletins