Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://huntr.dev/bounties/d8d6c259-a0f2-4209-a3b0-ecbf3eb092f4 | third party advisory exploit |
https://github.com/answerdev/answer/commit/1de3ec27e50ba7389c9449c59e8ea3a37a908ee4 | patch |