CVE-2021-41767: Private tunnel identifier may be included in the non-private details of active connections
Published Jan 11, 2022
·Updated
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
Affected Software
1 affected component
Apache Guacamole<=1.3.0
Event History
Jan 11, 2022
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-41767?
CVE-2021-41767 has a severity rating of medium due to potential unauthorized data exposure.
2
How do I fix CVE-2021-41767?
To fix CVE-2021-41767, upgrade Apache Guacamole to version 1.3.1 or later.
3
Who is affected by CVE-2021-41767?
CVE-2021-41767 affects users of Apache Guacamole versions 1.3.0 and older.
4
What functionalities are impacted by CVE-2021-41767?
CVE-2021-41767 may allow authenticated users to gain access to another user's connection details.
5
Is CVE-2021-41767 exploitable remotely?
CVE-2021-41767 is not strictly a remote vulnerability; it requires authenticated access to exploit.