Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11997

Опубликовано: 19 янв. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:*
Версия до 1.2.0 (включая)

EPSS

Процентиль: 66%
0.00509
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

CVSS3: 4.3
debian
около 5 лет назад

Apache Guacamole 1.2.0 and earlier do not consistently restrict access ...

EPSS

Процентиль: 66%
0.00509
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-276