GHSA-g7h2-wf29-2rw6

Suggest an improvement
Source
https://github.com/advisories/GHSA-g7h2-wf29-2rw6
Import Source
https://github.com/github/advisory-database/blob/main/GHSA-g7h2-wf29-2rw6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g7h2-wf29-2rw6
Withdrawn
2023-03-14T07:01:09Z
Published
2022-01-06T20:34:35Z
Modified
2023-03-14T07:01:09Z
Summary
Incorrect Default Permissions in Apache Guacamole
Details

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

References

Affected packages

Maven / org.apache.guacamole:guacamole-common-js

Package

Name
org.apache.guacamole:guacamole-common-js
View open source insights on deps.dev
Purl
pkg:maven/org.apache.guacamole/guacamole-common-js

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.0

Affected versions

0.*
0.9.10-incubating
0.9.12-incubating
0.9.13-incubating
0.9.14
1.*
1.0.0
1.1.0
1.2.0

Database specific

cvss
{
    "score": 4.3,
    "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
cwes
[
    {
        "cweId": "CWE-276",
        "description": "During installation, installed file permissions are set to allow anyone to modify those files.",
        "name": "Incorrect Default Permissions"
    }
]
ghsa
"https://github.com/advisories/GHSA-g7h2-wf29-2rw6"
source
"https://github.com/github/advisory-database/blob/main/GHSA-g7h2-wf29-2rw6.json"

Maven / org.apache.guacamole:guacamole-common

Package

Name
org.apache.guacamole:guacamole-common
View open source insights on deps.dev
Purl
pkg:maven/org.apache.guacamole/guacamole-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.0

Affected versions

0.*
0.9.10-incubating
0.9.13-incubating
0.9.14
1.*
1.0.0
1.1.0

Database specific

cvss
{
    "score": 4.3,
    "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
cwes
[
    {
        "cweId": "CWE-276",
        "description": "During installation, installed file permissions are set to allow anyone to modify those files.",
        "name": "Incorrect Default Permissions"
    }
]
ghsa
"https://github.com/advisories/GHSA-g7h2-wf29-2rw6"
source
"https://github.com/github/advisory-database/blob/main/GHSA-g7h2-wf29-2rw6.json"