Vulnerabilities > Apache > Guacamole > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-01-11 CVE-2021-41767 Information Exposure vulnerability in Apache Guacamole
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses.
network
low complexity
apache CWE-200
6.5
2021-01-19 CVE-2020-11997 Incorrect Default Permissions vulnerability in Apache Guacamole
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility.
network
low complexity
apache CWE-276
4.3
2020-07-02 CVE-2020-9498 Out-of-bounds Write vulnerability in multiple products
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels.
local
high complexity
apache fedoraproject debian CWE-787
6.7
2020-07-02 CVE-2020-9497 Improper Input Validation vulnerability in multiple products
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels.
local
high complexity
apache fedoraproject debian CWE-20
4.4
2017-02-02 CVE-2016-1566 Cross-site Scripting vulnerability in Apache Guacamole 0.9.8/0.9.9
Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
network
low complexity
apache CWE-79
5.4