PT-2013-3404 · Apache · Apache Rave
Andreas Guth
·
Publicado
2013-03-14
·
Atualizado
2022-05-17
·
CVE-2013-1814
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Rave versions 0.11 through 0.20
Description
The issue allows remote authenticated users to obtain sensitive information about all user accounts via the
offset parameter in the users/get program of the User RPC API. This can lead to the discovery of password hashes in the password field of a response.Recommendations
For Apache Rave versions 0.11 through 0.20, consider restricting access to the
users/get program in the User RPC API to minimize the risk of exploitation. As a temporary workaround, avoid using the offset parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Rave