{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T15:01:23.555","vulnerabilities":[{"cve":{"id":"CVE-2025-29868","sourceIdentifier":"security@apache.org","published":"2025-04-01T08:15:14.990","lastModified":"2025-04-15T13:07:54.393","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Private Data Structure Returned From A Public Method vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 1.4.2.\n\nIf a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.\nUsers are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed."},{"lang":"es","value":"Vulnerabilidad de estructura de datos privada devuelta desde un método público en Apache Answer. Este problema afecta a Apache Answer hasta la versión 1.4.2. Si un usuario utiliza una imagen referenciada externamente, al acceder a ella, el proveedor de la imagen podría obtener información privada sobre la dirección IP del usuario. Se recomienda actualizar a la versión 1.4.5, que soluciona el problema. En la nueva versión, los administradores pueden configurar si se puede mostrar contenido externo."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-495"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.2","matchCriteriaId":"29E2B105-1033-4FCE-8F05-20368605017D"}]}]}],"references":[{"url":"https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2025/04/01/2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2025/04/02/1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2025/04/10/3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]}]}}]}