CVE-2025-29868 – Apache Answer IP Address Disclosure

The following table lists the changes that have been made to the
CVE-2025-29868 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 01, 2025

    Action Type Old Value New Value
    Added Description Private Data Structure Returned From A Public Method vulnerability in Apache Answer.

    This issue affects Apache Answer: through 1.4.2.

    If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.
    Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

    Added CWE CWE-495
    Added Reference https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf
Share the Post:

Related Posts