VYPR

Maven package

org.apache.guacamole/guacamole-common

pkg:maven/org.apache.guacamole/guacamole-common

Vulnerabilities (2)

  • CVE-2018-1340Feb 7, 2019
    affected < 1.0.0fixed 1.0.0

    Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the

  • CVE-2017-3158Jan 18, 2018
    affected >= 0.9.5, < 0.9.11-incubatingfixed 0.9.11-incubating

    A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written