VDB
CVE-2025-29868
CVE-2025-29868
PUBLISHED
CVSS 1.100000023841858 LOW
Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
EPSS 0.87% · 55.5th percentile
Risk Scores
CVSS 4.0
1.100000023841858
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
EPSS Score
0.87%
55.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | answer | 0, 0 |
| github.com | apache/answer | 0, 0 |
| Apache Software Foundation | Apache Answer | 0, 0 |
Timeline
- Apr 1, 2025 CVE Published
- Apr 1, 2025 EPSS Score
- Apr 1, 2025 Coalition ESS Score
- Apr 1, 2025 PoC Published
- Apr 1, 2025 PoC Published
- Apr 1, 2025 PoC Published
- Apr 2, 2025 Coalition ESS Score
- Apr 2, 2025 PoC Published
- Apr 10, 2025 CVE Updated
- Apr 10, 2025 PoC Published
- Apr 14, 2025 EPSS Score
- Apr 27, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-29868 advisory
- https://github.com/apache/answer package
- http://www.openwall.com/lists/oss-security/2025/04/02/1 mailing_list
- https://github.com/apache/answer/issues/1250 url
- https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf url
- http://www.openwall.com/lists/oss-security/2025/04/01/2 url
- http://www.openwall.com/lists/oss-security/2025/04/10/3 url