← All CVEs

CVE-2013-1814

medium · 4

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

4
CVSS
73.8%
EPSS (exploit prob.)
99th
EPSS percentile
2013-03-14
Published

AV:N/AC:L/Au:S/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
apacherave0.11
apacherave0.12
apacherave0.13
apacherave0.14
apacherave0.15
apacherave0.16
apacherave0.17
apacherave0.18
apacherave0.19
apacherave0.20

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1814