← Back

CVE-2024-45719

nvd nist
Published: Nov 22, 2024Modified: Jun 17, 2026

JSON object

Loading...
2.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
Exploitability: 1.0 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.

Affected (1)

Products: Apache: Answer
1 product
Answer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.1

References (2)

Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.