Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
BID:58455
Info
Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
| Bugtraq ID: | 58455 |
| Class: | Design Error |
| CVE: |
CVE-2013-1814 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2013 12:00AM |
| Updated: | Mar 12 2013 12:00AM |
| Credit: | Andreas Guth of RWTH Aachen University |
| Vulnerable: |
Apache Rave 0.20 Apache Rave 0.11 |
| Not Vulnerable: |
Apache Rave 0.20.1 |
Discussion
Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
Rave is prone to an information disclosure vulnerability.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
Rave 0.11 through versions 0.20 are vulnerable.
Rave is prone to an information disclosure vulnerability.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
Rave 0.11 through versions 0.20 are vulnerable.
Exploit / POC
Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
An attacker can exploit this issue through readily available tools.
The following example request is available:
/app/api/rpc/users/get?offset=3DOFFSET
An attacker can exploit this issue through readily available tools.
The following example request is available:
/app/api/rpc/users/get?offset=3DOFFSET
References
Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
References:
References:
- [CVE-2013-1814] Apache Rave exposes User over API (SecLists.Org)
- Apache Rave Homepage (Apache Software Foundation)