๐Ÿ” CVE Alert

CVE-2025-24859

UNKNOWN 0.0

Apache Roller: Insufficient Session Expiration on Password Change

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing sessions remain active and usable. This allows continued access to the application through old sessions even after password changes, potentially enabling unauthorized access if credentials were compromised. This issue affects Apache Roller versions up to and including 6.1.4. The vulnerability is fixed in Apache Roller 6.1.5 by implementing centralized session management that properly invalidates all active sessions when passwords are changed or users are disabled.

CWE CWE-613
Vendor apache software foundation
Product apache roller
Published Apr 14, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache roller

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache roller are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Roller
1.0.0 < 6.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/vxv52vdr8nhtjlj6v02w43fdvo0cxw23 lists.apache.org: https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f openwall.com: http://www.openwall.com/lists/oss-security/2025/04/11/1

Credits

Haining Meng