Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

answerdev — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting answerdev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

answerdev operates as a developer-focused platform, primarily facilitating code collaboration and repository management for software engineering teams. Its core utility lies in streamlining version control and continuous integration workflows, making it a critical infrastructure component for many modern development pipelines. Historically, the platform has been associated with thirty-four recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving cross-site scripting (XSS) and insecure direct object references (IDOR). These flaws often stem from insufficient input validation within its web interface or API endpoints. While no single catastrophic breach has defined its history, the cumulative nature of these vulnerabilities highlights persistent challenges in securing complex web applications. Security audits frequently recommend strict access controls and regular patching to mitigate risks associated with privilege escalation and data exposure, ensuring the integrity of sensitive codebases hosted on the service.

Found 34 results / 34Clear Filters
Top products by answerdev: answerdev/answer
CVE IDTitleCVSSSeverityPublished
CVE-2023-4815 Missing Authentication for Critical Function in answerdev/answer — answerdev/answerCWE-306 6.5 -2023-09-07
CVE-2023-4127 Race Condition within a Thread in answerdev/answer — answerdev/answerCWE-366 7.5 -2023-08-03
CVE-2023-4126 Insufficient Session Expiration in answerdev/answer — answerdev/answerCWE-613 8.3 -2023-08-03
CVE-2023-4125 Weak Password Requirements in answerdev/answer — answerdev/answerCWE-521 7.5 -2023-08-03
CVE-2023-4124 Missing Authorization in answerdev/answer — answerdev/answerCWE-862--2023-08-03
CVE-2023-2590 Missing Authorization in answerdev/answer — answerdev/answerCWE-862 8.6 -2023-05-09
CVE-2023-1975 Insertion of Sensitive Information Into Sent Data in answerdev/answer — answerdev/answerCWE-201 6.5 -2023-04-11
CVE-2023-1974 Exposure of Sensitive Information Through Metadata in answerdev/answer — answerdev/answerCWE-1230 6.5 -2023-04-11
CVE-2023-1976 Password Aging with Long Expiration in answerdev/answer — answerdev/answerCWE-263 8.8 -2023-04-11
CVE-2023-1535 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-21
CVE-2023-1543 Insufficient Session Expiration in answerdev/answer — answerdev/answerCWE-613 9.8 -2023-03-21
CVE-2023-1542 Business Logic Errors in answerdev/answer — answerdev/answerCWE-840 7.1 -2023-03-21
CVE-2023-1541 Business Logic Errors in answerdev/answer — answerdev/answerCWE-840 7.1 -2023-03-21
CVE-2023-1540 Observable Response Discrepancy in answerdev/answer — answerdev/answerCWE-204 8.2 -2023-03-21
CVE-2023-1538 Observable Timing Discrepancy in answerdev/answer — answerdev/answerCWE-208 8.2 -2023-03-21
CVE-2023-1537 Authentication Bypass by Capture-replay in answerdev/answer — answerdev/answerCWE-294 9.8 -2023-03-21
CVE-2023-1536 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-21
CVE-2023-1539 Improper Restriction of Excessive Authentication Attempts in answerdev/answer — answerdev/answerCWE-307 8.2 -2023-03-21
CVE-2023-1245 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1237 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1238 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1239 Cross-site Scripting (XSS) - Reflected in answerdev/answer — answerdev/answerCWE-79 6.1 -2023-03-07
CVE-2023-1240 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1241 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1242 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1243 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-1244 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-03-07
CVE-2023-0934 Cross-site Scripting (XSS) - Stored in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-02-21
CVE-2023-0744 Improper Access Control in answerdev/answer — answerdev/answerCWE-284 7.6 -2023-02-08
CVE-2023-0743 Cross-site Scripting (XSS) - Generic in answerdev/answer — answerdev/answerCWE-79 5.4 -2023-02-08

This page lists every published CVE security advisory associated with answerdev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.