CVE Database
/

CVE-2020-11997

Back to search

CVE-2020-11997

Published: Jan 19, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

VendorProductVersions

n/a

Apache Guacamole

affected
Apache Guacamole 1.2.0 and older

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now