HIGH🇵🇱 Wersja polska

CVE-2026-60023

CVSS 7.5pub. 2026-08-05upd. 2026-08-06

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Apache Answer

    APP
    Apache
    < 2.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-60053CRITICAL9.1PL ✓same product

Apache Answer: nieważne klucze API nadal aktywne po degradacji konta

CVE-2024-22393CRITICAL9.1PL ✓same product

Apache Answer — atak Pixel Flood przez nieograniczony upload pliku

CVE-2026-48911HIGH7.5PL ✓same product

Apache Answer: przejęcie konta przez brak weryfikacji w external-login

CVE-2026-48834HIGH7.5PL ✓same product

Apache Answer — DoS przez nieprawidłowy nagłówek Accept-Language

CVE-2026-25700HIGH7.2same product

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache A...