CVE-2024-45719 – github.com/apache/incubator-answer
Package
Manager: go
Name: github.com/apache/incubator-answer
Vulnerable Version: >=0 <1.4.1
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
EPSS: 0.00068 pctl0.214
Details
Apache Answer: Predictable Authorization Token Using UUIDv1 Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.
Metadata
Created: 2024-11-22T21:32:14Z
Modified: 2024-11-27T21:56:44Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json
CWE IDs: ["CWE-326"]
Alternative ID: GHSA-mr95-vfcf-fx9p
Finding: F052
Auto approve: 1