4
CVSSv2

CVE-2020-11997

Published: 19/01/2021 Updated: 22/01/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Apache Guacamole 1.2.0 and previous versions do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache guacamole

Vendor Advisories

Debian Bug report logs - #1015986 guacamole-client: CVE-2021-41767 CVE-2021-43999 CVE-2020-11997 Package: src:guacamole-client; Maintainer for src:guacamole-client is Debian Remote Maintainers <pkg-remote-team@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 24 Jul 2022 19:03:01 UT ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SECURITY] CVE-2020-11997: Apache Guacamole: Inconsistent restriction of connection history visibility <!--X-Subject-Header-En ...