Private Data Structure Returned From A Public Method vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.4.2.

If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.
Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-9320 Apache Answer User Using External Images Potentially Discloses User Information
Github GHSA Github GHSA GHSA-wqcc-mfhw-53pc Apache Answer User Using External Images Potentially Discloses User Information
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Apr 2025 22:30:00 +0900

Type Values Removed Values Added
First Time appeared Apache
Apache answer
CPEs cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache answer

Fri, 11 Apr 2025 00:45:00 +0900

Type Values Removed Values Added
References

Thu, 03 Apr 2025 07:45:00 +0900


Wed, 02 Apr 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 17:15:00 +0900

Type Values Removed Values Added
Description Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Title Apache Answer: Using externally referenced images can leak user privacy.
Weaknesses CWE-495
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-04-10T15:03:07.021Z

Reserved: 2025-03-12T07:04:55.206Z

Link: CVE-2025-29868

cve-icon Vulnrichment

Updated: 2025-04-10T15:03:07.021Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-01T08:15:14.990

Modified: 2025-04-15T13:07:54.393

Link: CVE-2025-29868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses