SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11997

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility.

MEDIUM 4.3EPSS 1.24%

Does this matter?

Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.

Description

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.24% probability · 68th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
apache/guacamole
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.