CVE-2024-26578

CVE-2024-26578: Apache Answer: Repeated submission at registration created duplicate users with the same name

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-362
Published February 22, 2024
Last update March 20, 2025

CVSS base score

What the vulnerability does

Description

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. When users register, if they rapidly submit multiple registrations using scripts, it can result in the creation of multiple user accounts simultaneously with the same name. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

Key dates

Disclosure timeline

February 22, 2024 CVE published
March 20, 2025 Record updated