with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.6.0, which fixes this issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54722 | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.6.0, which fixes this issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 09 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache guacamole |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache guacamole |
Wed, 02 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Jul 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.6.0, which fixes this issue. | |
| Title | Apache Guacamole: Improper input validation of console codes | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:08:36.862Z
Reserved: 2024-05-10T07:46:23.307Z
Link: CVE-2024-35164
Updated: 2025-11-04T21:08:36.862Z
Status : Modified
Published: 2025-07-02T12:15:27.770
Modified: 2025-11-04T22:16:01.600
Link: CVE-2024-35164
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:24Z
EUVD