First published: Tue Apr 01 2025(Updated: )
Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Answer | <1.4.2 | |
go/github.com/apache/answer | <1.4.5 | 1.4.5 |
Apache Answer | <=1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29868 is classified as a medium severity vulnerability.
To fix CVE-2025-29868, upgrade Apache Answer to version 1.4.3 or later.
CVE-2025-29868 is a private data structure exposure vulnerability.
CVE-2025-29868 affects Apache Answer versions up to 1.4.2.
The impact of CVE-2025-29868 could allow external providers to access private user data.