First published: Thu Mar 14 2013(Updated: )
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
=0.11 | ||
=0.12 | ||
=0.13 | ||
=0.14 | ||
=0.15 | ||
=0.16 | ||
=0.17 | ||
=0.18 | ||
=0.19 | ||
=0.20 | ||
Apache Rave | =0.11 | |
Apache Rave | =0.12 | |
Apache Rave | =0.13 | |
Apache Rave | =0.14 | |
Apache Rave | =0.15 | |
Apache Rave | =0.16 | |
Apache Rave | =0.17 | |
Apache Rave | =0.18 | |
Apache Rave | =0.19 | |
Apache Rave | =0.20 | |
maven/org.apache.rave:rave-portal-resources | >=0.11<0.20.1 | 0.20.1 |
maven/org.apache.rave:rave-web | >=0.11<0.20.1 | 0.20.1 |
maven/org.apache.rave:rave-core | >=0.11<0.20.1 | 0.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.