CVE-2021-41767
published 2022-01-11CVE-2021-41767: Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.93%
77.7th percentile
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | guacamole | <= 1.3.0 | — |
| apache | guacamole | — | — |
| apache_software_foundation | apache_guacamole | unspecified – 1.3.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_apache6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Guacamole
ghsa_unreviewed·2022-02-15
CVE-2021-41767 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Guacamole
Exposure of Sensitive Information to an Unauthorized Actor in Apache Guacamole
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
OSV
CVE-2021-41767: Apache Guacamole 1
osv·2022-01-11·CVSS 6.5
CVE-2021-41767 [MEDIUM] CVE-2021-41767: Apache Guacamole 1
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
Apache
Apache guacamole: CVE-2021-41767
vendor_apache·CVSS 6.5
CVE-2021-41767 [MEDIUM] Apache guacamole: CVE-2021-41767
Apache guacamole: CVE-2021-41767
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user’s active use of that same connection. Acknowledgements: We would like to thank Damian Velardo (Australia and New Zealand Banking Group) for reporting this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-11
Published