Loading HuntDB...

CVE-2021-41767

UNKNOWN
Published 2022-01-11T22:10:11
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2021-41767. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed MODERATE

Exposure of Sensitive Information to an Unauthorized Actor in Apache Guacamole

GHSA-8jvg-8759-x9j6

Advisory Details

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Advisory provided by GitHub Security Advisory Database. Published: February 15, 2022, Modified: February 15, 2022

References

Published: 2022-01-11T22:10:11
Last Modified: 2024-08-04T03:15:29.360Z
Copied to clipboard!