CVE-2024-26578 Information
Feb 23, 2024
cve
Description
Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Repeated submission during registration resulted in the registration of the same user. When users register if they rapidly submit multiple registrations using scripts it can result in the creation of multiple user accounts simultaneously with the same name. Users are recommended to upgrade to version [1.2.5] which fixes the issue.
Reference
https://lists.apache.org/thread/ko0ksnznt2484lxt0zts2ygr82ldkhcb http://www.openwall.com/lists/oss-security/2024/02/22/3
Share on: