GHSA-wqcc-mfhw-53pc · Severity: low · Ecosystem: go — Apache Answer User Using External Images Potentially Discloses User Information
Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.
Conclusion & alert: CVE-2025-29868 is rated Moderate Risk (54/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.55%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-19 | 2.08% | 1.55% | -0.53% |
| 2 | 2026-05-10 | 2.24% | 2.08% | -0.16% |
| 3 | 2026-01-26 | — | 2.24% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-wqcc-mfhw-53pc · Severity: low · Ecosystem: go — Apache Answer User Using External Images Potentially Discloses User Information
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/04/01/2 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/04/02/1 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/04/10/3 | Mailing List |