Severity: moderate 

Affected versions:

- Apache Answer through 2.0.1

Description:

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in 
Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Deleted or pending answers could be retrieved by unauthorized users through the 
single-answer read path when the parent question remained visible, exposing 
answer content that should not have been accessible.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Credit:

yangxi (reporter)

References:

https://answer.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-60023


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to