Apache Answer是美国阿帕奇(Apache)基金会的一个社区平台。 Apache Answer 2.0.0及之前版本存在安全漏洞,该漏洞源于时间线相关API缺乏适当授权检查,可能导致普通认证用户访问已删除、私有或未批准内容及其修订历史,导致私人信息泄露给未经授权的行为者。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Answer | ≤ 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Answer | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49818 | Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object names | |
| CVE-2026-34905 | Apache Answer: Unlisted Questions Accessible via Direct API Access | |
| CVE-2026-34033 | Apache Answer: HTML Content Injection in Email | |
| CVE-2026-34031 | Apache Answer: The custom avatar was not properly validated | |
| CVE-2026-33582 | Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error | |
| CVE-2026-25688 | Apache Answer: XSS in AI Answer Rendering |
No comments yet