Description
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Remediation
References
http://archives.neohapsis.com/archives/bugtraq/2013-03/0078.html
http://www.exploit-db.com/exploits/24744/
Related Vulnerabilities
CVE-2020-7703 Vulnerability in npm package nis-utils
CVE-2022-41928 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2019-14772 Vulnerability in npm package verdaccio
CVE-2016-10533 Vulnerability in npm package express-restify-mongoose