Apache Answer
- <= 2.0.0
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Apache Answer versions prior to 2.0.0. This issue arises when a crafted TIFF image is uploaded, triggering excessive memory allocation during the decoding process. As a result, an authenticated user could cause the server process to crash.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the server process to crash.
Users are advised to upgrade to Apache Answer version 2.0.1 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.