Critical CVE-2025-24859 Vulnerability in Apache Roller (CVSS 10.0) Allows Continued Access Even After Password Changes
142/68 Thursday, April 17, 2025 A critical security vulnerability, CVE-2025-24859, has been disclosed in Apache Roller, a popular Java-based open-source blogging server. The flaw, which affects versions ≤6.1.4, has been assigned the maximum CVSS score of 10.0, indicating its severity. The vulnerability stems from unsafe session management, allowing authenticated sessions to remain active even after […]