First published: Thu Mar 14 2013(Updated: )
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
=0.11 | ||
=0.12 | ||
=0.13 | ||
=0.14 | ||
=0.15 | ||
=0.16 | ||
=0.17 | ||
=0.18 | ||
=0.19 | ||
=0.20 | ||
Apache Rave | =0.11 | |
Apache Rave | =0.12 | |
Apache Rave | =0.13 | |
Apache Rave | =0.14 | |
Apache Rave | =0.15 | |
Apache Rave | =0.16 | |
Apache Rave | =0.17 | |
Apache Rave | =0.18 | |
Apache Rave | =0.19 | |
Apache Rave | =0.20 | |
maven/org.apache.rave:rave-portal-resources | >=0.11<0.20.1 | 0.20.1 |
maven/org.apache.rave:rave-web | >=0.11<0.20.1 | 0.20.1 |
maven/org.apache.rave:rave-core | >=0.11<0.20.1 | 0.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1814 is classified as a medium severity vulnerability that allows exposure of sensitive information.
To fix CVE-2013-1814, upgrade Apache Rave to version 0.20.1 or higher.
CVE-2013-1814 affects authenticated users of Apache Rave versions 0.11 through 0.20.
CVE-2013-1814 can expose sensitive information including user password hashes.
Yes, a patch for CVE-2013-1814 is available in version 0.20.1 of Apache Rave.