menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

4d

read

166

img
dot

Image Credit: Securityaffairs

Critical Apache Roller flaw allows to retain unauthorized access even after a password change

  • A critical flaw (CVE-2025-24859, CVSS 10) in Apache Roller lets attackers keep access even after password changes. All versions ≤6.1.4 are affected.
  • A critical vulnerability, tracked as CVE-2025-24859 (CVSS score of 10.0), affects the Apache Roller open-source, Java-based blogging server software.
  • The flaw is a session management issue that impacts in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes.
  • In early April, experts warned of another critical vulnerability impacting Apache Parquet’s Java Library. The vulnerability, tracked as CVE-2025-30065 (CVSS score of 10.0), could allow remote code execution.

Read Full Article

like

10 Likes

For uninterrupted reading, download the app