Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
{
"binaries": [
{
"binary_version": "0.8.3-2",
"binary_name": "guacd"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-dev"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac5"
}
]
}
{
"binaries": [
{
"binary_version": "0.9.9-2build1",
"binary_name": "guacd"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-telnet0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-dev"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac11"
}
]
}
{
"binaries": [
{
"binary_version": "1.3.0-1.1",
"binary_name": "guacd"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-telnet0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-dev"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac19"
}
]
}
{
"binaries": [
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "guacd"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-rdp0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-ssh0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-telnet0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-vnc0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-dev"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac19t64"
}
]
}