Major Apache Roller Flaw (CVSS 10.0) Facilitates Unauthorized Session Persistence
An urgent security loophole has been revealed in the Apache Roller, a Java-powered platform for blogging, which may empower unauthorized individuals to maintain access without proper authorization, even subsequent to altering a password.
This vulnerability, labeled as CVE-2025-24859, has been rated with a CVSS score of 10.0, demonstrating the utmost criticality. It impacts every iteration of Roller until version 6.1.4.
This vulnerability, labeled as CVE-2025-24859, has been rated with a CVSS score of 10.0, demonstrating the utmost criticality. It impacts every iteration of Roller until version 6.1.4.
