Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
History

Tue, 15 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache answer
CPEs cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache answer

Thu, 10 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
References

Wed, 02 Apr 2025 22:45:00 +0000


Tue, 01 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Title Apache Answer: Using externally referenced images can leak user privacy.
Weaknesses CWE-495
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-04-10T15:03:07.021Z

Reserved: 2025-03-12T07:04:55.206Z

Link: CVE-2025-29868

cve-icon Vulnrichment

Updated: 2025-04-10T15:03:07.021Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-01T08:15:14.990

Modified: 2025-04-15T13:07:54.393

Link: CVE-2025-29868

cve-icon Redhat

No data.