Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr7r-vg3c-54r5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Missing Encryption of Sensitive Data in Apache Guacamole

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.

Пакеты

Наименование

org.apache.guacamole:guacamole-common

maven
Затронутые версииВерсия исправления

< 1.0.0

1.0.0

EPSS

Процентиль: 70%
0.00633
Низкий

7.5 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.

CVSS3: 7.5
nvd
почти 7 лет назад

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.

CVSS3: 7.5
debian
почти 7 лет назад

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage ...

EPSS

Процентиль: 70%
0.00633
Низкий

7.5 High

CVSS3

Дефекты

CWE-311