logo

CVE-2024-45719 github.com/apache/incubator-answer

Package

Manager: go
Name: github.com/apache/incubator-answer
Vulnerable Version: >=0 <1.4.1

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

EPSS: 0.00068 pctl0.214

Details

Apache Answer: Predictable Authorization Token Using UUIDv1 Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.

Metadata

Created: 2024-11-22T21:32:14Z
Modified: 2024-11-27T21:56:44Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json
CWE IDs: ["CWE-326"]
Alternative ID: GHSA-mr95-vfcf-fx9p
Finding: F052
Auto approve: 1