Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

answerdev — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting answerdev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

answerdev operates as a developer-focused platform, primarily facilitating code collaboration and repository management for software engineering teams. Its core utility lies in streamlining version control and continuous integration workflows, making it a critical infrastructure component for many modern development pipelines. Historically, the platform has been associated with thirty-four recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving cross-site scripting (XSS) and insecure direct object references (IDOR). These flaws often stem from insufficient input validation within its web interface or API endpoints. While no single catastrophic breach has defined its history, the cumulative nature of these vulnerabilities highlights persistent challenges in securing complex web applications. Security audits frequently recommend strict access controls and regular patching to mitigate risks associated with privilege escalation and data exposure, ensuring the integrity of sensitive codebases hosted on the service.

Found 34 results / 34 Clear Filters
Top products by answerdev: answerdev/answer
CVE ID Title CVSS Severity Published
CVE-2023-4815 Missing Authentication for Critical Function in answerdev/answer — answerdev/answer CWE-306 6.5 - 2023-09-07
CVE-2023-4127 Race Condition within a Thread in answerdev/answer — answerdev/answer CWE-366 7.5 - 2023-08-03
CVE-2023-4126 Insufficient Session Expiration in answerdev/answer — answerdev/answer CWE-613 8.3 - 2023-08-03
CVE-2023-4125 Weak Password Requirements in answerdev/answer — answerdev/answer CWE-521 7.5 - 2023-08-03
CVE-2023-4124 Missing Authorization in answerdev/answer — answerdev/answer CWE-862 - - 2023-08-03
CVE-2023-2590 Missing Authorization in answerdev/answer — answerdev/answer CWE-862 8.6 - 2023-05-09
CVE-2023-1975 Insertion of Sensitive Information Into Sent Data in answerdev/answer — answerdev/answer CWE-201 6.5 - 2023-04-11
CVE-2023-1974 Exposure of Sensitive Information Through Metadata in answerdev/answer — answerdev/answer CWE-1230 6.5 - 2023-04-11
CVE-2023-1976 Password Aging with Long Expiration in answerdev/answer — answerdev/answer CWE-263 8.8 - 2023-04-11
CVE-2023-1535 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-21
CVE-2023-1543 Insufficient Session Expiration in answerdev/answer — answerdev/answer CWE-613 9.8 - 2023-03-21
CVE-2023-1542 Business Logic Errors in answerdev/answer — answerdev/answer CWE-840 7.1 - 2023-03-21
CVE-2023-1541 Business Logic Errors in answerdev/answer — answerdev/answer CWE-840 7.1 - 2023-03-21
CVE-2023-1540 Observable Response Discrepancy in answerdev/answer — answerdev/answer CWE-204 8.2 - 2023-03-21
CVE-2023-1538 Observable Timing Discrepancy in answerdev/answer — answerdev/answer CWE-208 8.2 - 2023-03-21
CVE-2023-1537 Authentication Bypass by Capture-replay in answerdev/answer — answerdev/answer CWE-294 9.8 - 2023-03-21
CVE-2023-1536 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-21
CVE-2023-1539 Improper Restriction of Excessive Authentication Attempts in answerdev/answer — answerdev/answer CWE-307 8.2 - 2023-03-21
CVE-2023-1245 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1237 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1238 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1239 Cross-site Scripting (XSS) - Reflected in answerdev/answer — answerdev/answer CWE-79 6.1 - 2023-03-07
CVE-2023-1240 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1241 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1242 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1243 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-1244 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-03-07
CVE-2023-0934 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-02-21
CVE-2023-0744 Improper Access Control in answerdev/answer — answerdev/answer CWE-284 7.6 - 2023-02-08
CVE-2023-0743 Cross-site Scripting (XSS) - Generic in answerdev/answer — answerdev/answer CWE-79 5.4 - 2023-02-08

This page lists every published CVE security advisory associated with answerdev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.