CVE-2013-1814
Last modified
CVE-2013-1814 is a vulnerability of currently unknown severity. The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.. EPSS estimates a 73.22% chance of exploitation in the next 30 days.
Description
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Rave | 0.11 |
| Apache | Rave | 0.12 |
| Apache | Rave | 0.13 |
| Apache | Rave | 0.14 |
| Apache | Rave | 0.15 |
| Apache | Rave | 0.16 |
| Apache | Rave | 0.17 |
| Apache | Rave | 0.18 |
| Apache | Rave | 0.19 |
| Apache | Rave | 0.20 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1814?
How severe is CVE-2013-1814?
How do I fix CVE-2013-1814?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1808Cross-site scripting (XSS) vulnerability in ZeroClipboard.sw…
- CVE-2013-1809Gambas before 3.4.0 allows remote attackers to move or manip…7.5
- CVE-2013-1810Multiple cross-site scripting (XSS) vulnerabilities in core/…
- CVE-2013-1811An access control issue in MantisBT before 1.2.13 allows use…4.3
- CVE-2013-1812The ruby-openid gem before 2.2.2 for Ruby allows remote Open…
- CVE-2013-1813util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permiss…
- CVE-2013-1815A flaw was found in PackStack. This vulnerability allows a l…6.1
- CVE-2013-1816MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remo…7.5
- CVE-2013-1817MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an…7.5
- CVE-2013-1818maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allo…
- CVE-2013-1819The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux …
- CVE-2013-1820tuned before 2.x allows local users to kill running processe…5.5
Are you affected by CVE-2013-1814?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
