logo

Max Severity Bug in Apache Roller Enabled Persistent Access

ID: 05b13203-3ec9-5b74-baf5-b000dfde1e28

STIX ID: report--05b13203-3ec9-5b74-baf5-b000dfde1e28

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-04-15

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

A critical session-management vulnerability (CVE-2025-24859) in Apache Roller versions 6.1.4 and earlier allowed active sessions to remain valid after password changes, enabling persistent unauthorized access and possible administrative control; Apache released Roller 6.1.5 to fix the issue by centrally invalidating sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.