CVE-2024-22393

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

History

05 May 2025, 21:00

Type Values Removed Values Added
CPE cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
First Time Apache
Apache answer
References () http://www.openwall.com/lists/oss-security/2024/02/22/1 - () http://www.openwall.com/lists/oss-security/2024/02/22/1 - Third Party Advisory
References () https://lists.apache.org/thread/f58l6dr4r74hl6o71gn47kmn44vw12cv - () https://lists.apache.org/thread/f58l6dr4r74hl6o71gn47kmn44vw12cv - Vendor Advisory

13 Feb 2025, 18:16

Type Values Removed Values Added
Summary (en) Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue. (en) Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

21 Nov 2024, 08:56

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/22/1 - () http://www.openwall.com/lists/oss-security/2024/02/22/1 -
References () https://lists.apache.org/thread/f58l6dr4r74hl6o71gn47kmn44vw12cv - () https://lists.apache.org/thread/f58l6dr4r74hl6o71gn47kmn44vw12cv -

01 Aug 2024, 13:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

22 Feb 2024, 16:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/22/1 -
Summary
  • (es) Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en Apache Answer. Este problema afecta a Apache Answer: hasta 1.2.1. El ataque de inundación de píxeles mediante la carga de archivos de píxeles de gran tamaño provocará que el servidor se quede sin memoria. Un usuario que haya iniciado sesión puede provocar un ataque de este tipo al cargar una imagen al publicar contenido. Se recomienda a los usuarios actualizar a la versión [1.2.5], que soluciona el problema.

22 Feb 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 10:15

Updated : 2025-05-05 21:00


NVD link : CVE-2024-22393

Mitre link : CVE-2024-22393

CVE.ORG link : CVE-2024-22393


JSON object : View

Products Affected

apache

  • answer
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type