Description
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28775 | Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection. |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T03:15:29.360Z
Reserved: 2021-09-28T00:00:00.000Z
Link: CVE-2021-41767
No data.
Status : Modified
Published: 2022-01-11T22:15:07.570
Modified: 2024-11-21T06:26:43.560
Link: CVE-2021-41767
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD