BIT-guacamole-2020-11997
Dashboard / Vulnerabilities / BIT-guacamole-2020-11997
BIT-guacamole-2020-11997
Published: 6 Mar 2024Last Modified: 6 Mar 2024
Summary:
Details: Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.
Affected packages
Package
Name: guacamole
Purl: pkg:bitnami/guacamole
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.2.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
