CVE-2025-29868 is a medium-severity vulnerability in Apache Answer versions up to 1.4.2, where a private data structure is exposed through a public method. This allows external image providers to obtain the IP addresses of users accessing externally referenced images. The CVSS score is 6.5, indicating a network-based attack with low complexity, resulting in potential disclosure of user IP addresses. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to Apache Answer version 1.4.5, which includes a fix allowing administrators to control external content display.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.2CPE matchmatch criteria | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.