Max Severity Bug in Apache Roller Enabled Persistent Access
ID: 05b13203-3ec9-5b74-baf5-b000dfde1e28
STIX ID: report--05b13203-3ec9-5b74-baf5-b000dfde1e28
Feed Name: Dark Reading
Threat Score
A critical session-management vulnerability (CVE-2025-24859) in Apache Roller versions 6.1.4 and earlier allowed active sessions to remain valid after password changes, enabling persistent unauthorized access and possible administrative control; Apache released Roller 6.1.5 to fix the issue by centrally invalidating sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
