PT-2025-14083 · Apache · Apache Answer
Hamed Kohi
+1
·
Published
2025-04-01
·
Updated
2025-04-05
·
CVE-2025-29868
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Answer versions through 1.4.2
Apache Answer versions prior to 1.4.5
Description
This issue affects users who use externally referenced images. When a user accesses such an image, the provider of the image may obtain private information about the IP address of the accessing user.
Recommendations
For Apache Answer versions through 1.4.2, upgrade to version 1.4.5, which fixes the issue and allows administrators to set whether external content can be displayed.
For Apache Answer versions prior to 1.4.5, upgrade to version 1.4.5 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Answer