Data Exposure in Apache Answer Allows Inadvertent Leakage of User Information
CVE-2025-29868
6.5MEDIUM
What is CVE-2025-29868?
A vulnerability in Apache Answer allows private data to be retrieved through a public method, specifically when users access externally referenced images. This can lead to the unintentional exposure of sensitive information, such as the user's IP address, to the image provider. To mitigate this risk, users are advised to update to version 1.4.5, which introduces administrative controls to manage the display of external content.
Affected Version(s)
Apache Answer 0 <= 1.4.2