CVE-2013-1814

medium Apache
CVSS v3 Base Score
4.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Score
83.0%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Published: March 14, 2013 (4810 days ago)
Last Modified: April 29, 2026
Vendor: Apache
Source: NVD

Description

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

CWE

CWE-200

Affected Products

apache rave

References