Description
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Remediation
References
http://archives.neohapsis.com/archives/bugtraq/2013-03/0078.html
http://www.exploit-db.com/exploits/24744/
Related Vulnerabilities
CVE-2020-11020 Vulnerability in maven package org.webjars.npm:faye
CVE-2020-7691 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2019-5786 Vulnerability in npm package electron
CVE-2022-3952 Vulnerability in maven package com.manydesigns:portofino-microservice-launcher
CVE-2022-39243 Vulnerability in maven package com.zaxxer:nuprocess