CVE Published: 11/01/2022 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Guacamole Status : PUBLISHED
CVE-2021-41767 Description
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user\'s active use of that same connection.