QID 996791
Date Published: 2024-02-05
QID 996791: Java (Maven) Security Update for org.apache.rave:rave-core (GHSA-428j-q447-47rw)
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-428j-q447-47rw for updates and patch information.
Vendor References
- GHSA-428j-q447-47rw -
github.com/advisories/GHSA-428j-q447-47rw
CVEs related to QID 996791
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-428j-q447-47rw | org.apache.rave:rave-core |
|