CVE-2024-40761

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
25/09/2024
Last modified:
10/07/2025

Description

Inadequate Encryption Strength vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 1.3.5.<br /> <br /> Using the MD5 value of a user&amp;#39;s email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead.<br /> Users are recommended to upgrade to version 1.4.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* 1.3.5 (including)