Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-29868

Опубликовано: 01 апр. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Private Data Structure Returned From A Public Method vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.4.2.

If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
Версия до 1.4.2 (включая)

EPSS

Процентиль: 59%
0.00937
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-495

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

Apache Answer User Using External Images Potentially Discloses User Information

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость Q&A-платформы Apache Answer, связанная с возвратом ссылки на защищённые данные из публичного метода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 59%
0.00937
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-495