CVE-2025-24859 - CVE House
Back to Database
Status published Low CVE-2025-24859

Apache Roller: Insufficient Session Expiration on Password Change

Vulnerability Description

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing sessions remain active and usable. This allows continued access to the application through old sessions even after password changes, potentially enabling unauthorized access if credentials were compromised. This issue affects Apache Roller versions up to and including 6.1.4. The vulnerability is fixed in Apache Roller 6.1.5 by implementing centralized session management that properly invalidates all active sessions when passwords are changed or users are disabled.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24859

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Haining Meng

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Roller
Vulnerable Versions:
1.0.0

Timeline

Official Publish: April 14th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)