CVE-2025-29868

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

History

15 Apr 2025, 13:07

Type Values Removed Values Added
References () https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf - () https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/04/01/2 - () http://www.openwall.com/lists/oss-security/2025/04/01/2 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/04/02/1 - () http://www.openwall.com/lists/oss-security/2025/04/02/1 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/04/10/3 - () http://www.openwall.com/lists/oss-security/2025/04/10/3 - Mailing List
First Time Apache
Apache answer
CPE cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

10 Apr 2025, 15:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/10/3 -

02 Apr 2025, 22:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/01/2 -
  • () http://www.openwall.com/lists/oss-security/2025/04/02/1 -
Summary
  • (es) Vulnerabilidad de estructura de datos privada devuelta desde un método público en Apache Answer. Este problema afecta a Apache Answer hasta la versión 1.4.2. Si un usuario utiliza una imagen referenciada externamente, al acceder a ella, el proveedor de la imagen podría obtener información privada sobre la dirección IP del usuario. Se recomienda actualizar a la versión 1.4.5, que soluciona el problema. En la nueva versión, los administradores pueden configurar si se puede mostrar contenido externo.

01 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

01 Apr 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 08:15

Updated : 2025-04-15 13:07


NVD link : CVE-2025-29868

Mitre link : CVE-2025-29868

CVE.ORG link : CVE-2025-29868


JSON object : View

Products Affected

apache

  • answer
CWE
CWE-495

Private Data Structure Returned From A Public Method