Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2019-02-07T22:00:00Z
Updated: 2024-09-16T19:20:49.021Z
Reserved: 2017-12-07T00:00:00
Link: CVE-2018-1340
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-02-07T22:29:00.287
Modified: 2024-11-21T03:59:39.510
Link: CVE-2018-1340
Redhat
No data.