Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://lists.apache.org/thread/5l31k4jmzdsfz0xt8osrbl878gb3b7ro | mailing list vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/11/6 | third party advisory mailing list |