Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13cjdyLXZnM2MtNTRyNc4AASr6
Missing Encryption of Sensitive Data in Apache Guacamole
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.
Permalink: https://github.com/advisories/GHSA-wr7r-vg3c-54r5JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cjdyLXZnM2MtNTRyNc4AASr6
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: over 1 year ago
CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-wr7r-vg3c-54r5, CVE-2018-1340
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-1340
- https://lists.apache.org/thread.html/af1632e13dd9acf7537546660cae9143cbb10fdd2f9bb0832a690979@%3Cannounce.guacamole.apache.org%3E
- http://www.securityfocus.com/bid/106768
- https://github.com/advisories/GHSA-wr7r-vg3c-54r5
Affected Packages
maven:org.apache.guacamole:guacamole-common
Dependent packages: 1Dependent repositories: 66
Downloads:
Affected Version Ranges: < 1.0.0
Fixed in: 1.0.0
All affected versions: 0.9.14
All unaffected versions: 1.0.0, 1.1.0, 1.3.0, 1.4.0, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5