Major Apache Roller Flaw (CVSS 10.0) Facilitates Unauthorized Session Persistence

An urgent security loophole has been revealed in the Apache Roller, a Java-powered platform for blogging, which may empower unauthorized individuals to maintain access without proper authorization, even subsequent to altering a password.

An urgent security loophole has been revealed in the Apache Roller, a Java-powered platform for blogging, which may empower unauthorized individuals to maintain access without proper authorization, even subsequent to altering a password.
This vulnerability, labeled as CVE-2025-24859, has been rated with a CVSS score of 10.0, demonstrating the utmost criticality. It impacts every iteration of Roller until version 6.1.4.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.