-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from using MD5 hashing for email addresses in Gravatar URLs. The commit diff shows: 1) Removal of 'md5' package from dependencies 2) Replacement of MD5(str) with sha256(str) in the profile component 3) Security advisory explicitly states MD5 usage was the vulnerability. The key vulnerable function is the MD5 hash generation in index.tsx that processes user emails before sending them to Gravatar.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/apache/incubator-answer | go | < 1.4.0 | 1.4.0 |
Ongoing coverage of React2Shell