CVE 6.5 MEDIUM

Apache Answer: The custom avatar was not properly validated_CVE-2026-34031

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Basic Information

ID CVE-2026-34031
Source apache
Published Jun 9, 2026 at 07:34
Modified Jun 9, 2026 at 15:12

Affected Product

Vendor Apache Software Foundation
Product Apache Answer
Affected Versions Apache Software Foundation Apache Answer 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.