Loading HuntDB...

GHSA-mr95-vfcf-fx9p

GitHub Security Advisory

Apache Answer: Predictable Authorization Token Using UUIDv1

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Inadequate Encryption Strength vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.4.0.

The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable.
Users are recommended to upgrade to version 1.4.1, which fixes the issue.

Affected Packages

Go github.com/apache/incubator-answer
Affected versions: 0 (fixed in 1.4.1)

Related CVEs

Key Information

GHSA ID
GHSA-mr95-vfcf-fx9p
Published
November 22, 2024 9:32 PM
Last Modified
November 27, 2024 9:56 PM
CVSS Score
2.5 /10
Primary Ecosystem
Go
Primary Package
github.com/apache/incubator-answer
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.