356
VMScore

CVE-2021-41767

Published: 11/01/2022 Updated: 14/01/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache guacamole

Vendor Advisories

Debian Bug report logs - #1015986 guacamole-client: CVE-2021-41767 CVE-2021-43999 CVE-2020-11997 Package: src:guacamole-client; Maintainer for src:guacamole-client is Debian Remote Maintainers <pkg-remote-team@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 24 Jul 2022 19:03:01 UT ...