Private Data Structure Returned From A Public Method vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.2.
If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.
Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache answer |
|
| CPEs | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache answer |
Thu, 10 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 02 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed. | |
| Title | Apache Answer: Using externally referenced images can leak user privacy. | |
| Weaknesses | CWE-495 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2025-04-01T07:56:28.633Z
Updated: 2025-04-10T15:03:07.021Z
Reserved: 2025-03-12T07:04:55.206Z
Link: CVE-2025-29868
Updated: 2025-04-10T15:03:07.021Z
Status : Analyzed
Published: 2025-04-01T08:15:14.990
Modified: 2025-04-15T13:07:54.393
Link: CVE-2025-29868
No data.