GHSA-428j-q447-47rw
Dashboard / Vulnerabilities / GHSA-428j-q447-47rw
Summary: Apache Rave information disclosure vulnerability
Details: The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-1814, https://github.com/apache/rave/commit/546edbaacfcb7b3fcc81aafe37a5c58e401b66c6, https://github.com/apache/rave, https://web.archive.org/web/20130512040207/http://archives.neohapsis.com/archives/bugtraq/2013-03/0078.html, http://archives.neohapsis.com/archives/bugtraq/2013-03/0078.html, http://www.exploit-db.com/exploits/24744
Affected packages
Package
Name: org.apache.rave:rave-core
Purl: pkg:maven/org.apache.rave/rave-core
Affected ranges
Type: ECOSYSTEM
Events:
