VDB

CVE-2025-29868

CVE-2025-29868 PUBLISHED CVSS 1.100000023841858 LOW

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

EPSS 0.87% · 55.5th percentile

Risk Scores

CVSS 4.0
1.100000023841858
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
EPSS Score
0.87%
55.5th percentile

Affected Products

VendorProductVersions
apacheanswer0, 0
github.comapache/answer0, 0
Apache Software FoundationApache Answer0, 0

Timeline

  • Apr 1, 2025 CVE Published
  • Apr 1, 2025 EPSS Score
  • Apr 1, 2025 Coalition ESS Score
  • Apr 1, 2025 PoC Published
  • Apr 1, 2025 PoC Published
  • Apr 1, 2025 PoC Published
  • Apr 2, 2025 Coalition ESS Score
  • Apr 2, 2025 PoC Published
  • Apr 10, 2025 CVE Updated
  • Apr 10, 2025 PoC Published
  • Apr 14, 2025 EPSS Score
  • Apr 27, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›