logo

Apache Answer Vulnerabilities and Security Flaws Fixed

ID: 523a80fa-95f3-5ab4-a7a5-932881e7940f

STIX ID: report--523a80fa-95f3-5ab4-a7a5-932881e7940f

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Do Son

...
...

This advisory reports multiple serious vulnerabilities in an Apache Q&A tool — a critical XSS that can execute scripts and lead to data theft, token validation failures allowing reuse of admin tokens, Timeline API path checks that leak private data, a TIFF-based memory exhaustion crash, and HTML injection in email alerts — and urges immediate upgrade to Apache Answer 2.0.1 to remediate these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.