Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-43999

Опубликовано: 11 янв. 2022
Источник: debian
EPSS Низкий

Описание

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
guacamole-clientremovedpackage
guacamole-clientnot-affectedstretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/01/11/7

EPSS

Процентиль: 80%
0.01358
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.

CVSS3: 8.8
nvd
около 4 лет назад

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.

CVSS3: 8.8
github
почти 4 года назад

Improper Authentication in Apache Guacamole

EPSS

Процентиль: 80%
0.01358
Низкий