CVE-2025-29868

CVE-2025-29868: Apache Answer: Using externally referenced images can leak user privacy.

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-495
Published April 1, 2025
Last update April 10, 2025

CVSS base score

What the vulnerability does

Description

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

Key dates

Disclosure timeline

April 1, 2025 CVE published
April 10, 2025 Record updated