Known Vulnerabilities for Guacamole by Apache
Listed below are 9 of the newest known vulnerabilities associated with "Guacamole" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-41767 | Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST ... | 6.5 - MEDIUM | 2022-01-11 | 2022-01-14 |
| CVE-2021-22898 | curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPT... | 3.1 - LOW | 2021-06-11 | 2024-03-27 |
| CVE-2020-11997 | Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If mul... | 4.3 - MEDIUM | 2021-01-19 | 2021-01-22 |
| CVE-2020-9498 | Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. ... | 6.7 - MEDIUM | 2020-07-02 | 2023-11-07 |
| CVE-2020-9497 | Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a use... | 4.4 - MEDIUM | 2020-07-02 | 2023-11-07 |
| CVE-2019-19603 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. | 7.5 - HIGH | 2019-12-09 | 2023-11-07 |
| CVE-2018-1340 | Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "s... | 7.5 - HIGH | 2019-02-07 | 2023-11-07 |
| CVE-2017-3158 | A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of... | 8.1 - HIGH | 2018-01-18 | 2023-11-07 |
| CVE-2016-1566 | Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a... | 5.4 - MEDIUM | 2017-02-02 | 2021-05-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Guacamole | 1.3.0 | rc1 | All | All |
| Application | Apache | Guacamole | 1.3.0 | - | All | All |
| Application | Apache | Guacamole | 1.2.0 | rc1 | All | All |
| Application | Apache | Guacamole | 1.2.0 | - | All | All |
| Application | Apache | Guacamole | 1.1.0 | rc1 | All | All |
| Application | Apache | Guacamole | 1.1.0 | All | All | All |
| Application | Apache | Guacamole | 1.0.0 | rc1 | All | All |
| Application | Apache | Guacamole | 1.0.0 | All | All | All |
| Application | Apache | Guacamole | 0.9.9 | All | All | All |
| Application | Apache | Guacamole | 0.9.8 | All | All | All |
| Application | Apache | Guacamole | 0.9.7 | All | All | All |
| Application | Apache | Guacamole | 0.9.6 | All | All | All |
| Application | Apache | Guacamole | 0.9.5 | All | All | All |
| Application | Apache | Guacamole | 0.9.4 | All | All | All |
| Application | Apache | Guacamole | 0.9.3 | All | All | All |
| Application | Apache | Guacamole | 0.9.2 | All | All | All |
| Application | Apache | Guacamole | 0.9.14 | rc1 | All | All |
| Application | Apache | Guacamole | 0.9.14 | All | All | All |
| Application | Apache | Guacamole | 0.9.13-incubating | All | All | All |
| Application | Apache | Guacamole | 0.9.12-incubating | All | All | All |