Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11997

Опубликовано: 19 янв. 2021
Источник: debian
EPSS Низкий

Описание

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
guacamole-clientremovedpackage
guacamole-clientignoredstretchpackage

Примечания

  • https://lists.apache.org/thread.html/r1a9ae9d1608c9f846875c4191cd738f95543d1be06b52dc1320e8117%40%3Cannounce.guacamole.apache.org%3E

  • https://issues.apache.org/jira/browse/GUACAMOLE-1123

  • https://github.com/apache/guacamole-client/pulls?q=is%3Apr+guacamole-1123+is%3Aclosed

  • https://github.com/glyptodon/guacamole-client/pull/453

  • https://enterprise.glyptodon.com/doc/latest/cve-2020-11997-inconsistent-restriction-of-connection-history-visibility-31424710.html

  • https://enterprise.glyptodon.com/doc/1.x/changelog-950368.html#id-.Changelogv1.x-1.14

EPSS

Процентиль: 66%
0.00509
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

CVSS3: 4.3
nvd
около 5 лет назад

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

EPSS

Процентиль: 66%
0.00509
Низкий
Уязвимость CVE-2020-11997