CVE-2013-1814
Apache Rave information disclosure vulnerability
EPSS 73.2%
Description
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
How to fix CVE-2013-1814
To remediate CVE-2013-1814, upgrade the affected package to a fixed version below.
- Maven/org.apache.rave:rave-core—upgrade to 0.20.1 or later
- Maven/org.apache.rave:rave-portal-resources—upgrade to 0.20.1 or later
- —upgrade to 0.20.1 or later
Is CVE-2013-1814 being exploited?
Likely — EPSS is 73.2%, placing CVE-2013-1814 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (3)
- >= 0.11, < 0.20.1
- >= 0.11, < 0.20.1
- >= 0.11, < 0.20.1