Unrestricted Upload of File with Dangerous Type Vulnerability Affects Apache Answer
CVE-2024-22393
9.1CRITICAL
What is CVE-2024-22393?
The Apache Answer application has a vulnerability that allows users to upload dangerous file types without restriction. This issue can be exploited by a logged-in user to upload large pixel files, which leads to a pixel flood attack, potentially causing the server to run out of memory. It is crucial for users to update their installations to version 1.2.5 or higher to mitigate this risk.
Affected Version(s)
Apache Answer 0 <= 1.2.1