CVE-2025-29868CWE-495

Apache Answer: Using externally referenced images can leak user privacy.

Medium · published April 1, 2025

CVSS v3.1
6.5
EPSS
1%
Percentile
58.6
In the wild
Unconfirmed
What it is

Private Data Structure Returned From A Public Method vulnerability in Apache Answer.

This issue affects Apache Answer: through 1.4.2.

If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.

Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00937 · 58.6th percentile
Weakness
CWE-495 · Private Data Structure Returned From A Public Method
Published
2025-04-01T07:56Z
EPSS history
Timeline
  • 01 APR 07:56Z
    Apache Answer: Using externally referenced images can leak user privacy.
    cvelistv5