Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact with another user's active use of that same connection.
{ "binaries": [ { "binary_version": "0.8.3-2", "binary_name": "guacd" }, { "binary_version": "0.8.3-2", "binary_name": "libguac-client-rdp0" }, { "binary_version": "0.8.3-2", "binary_name": "libguac-client-ssh0" }, { "binary_version": "0.8.3-2", "binary_name": "libguac-client-vnc0" }, { "binary_version": "0.8.3-2", "binary_name": "libguac-dev" }, { "binary_version": "0.8.3-2", "binary_name": "libguac5" } ] }
{ "binaries": [ { "binary_version": "0.9.9-2build1", "binary_name": "guacd" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac-client-rdp0" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac-client-ssh0" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac-client-telnet0" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac-client-vnc0" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac-dev" }, { "binary_version": "0.9.9-2build1", "binary_name": "libguac11" } ] }
{ "binaries": [ { "binary_version": "1.3.0-1.1", "binary_name": "guacd" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac-client-rdp0" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac-client-ssh0" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac-client-telnet0" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac-client-vnc0" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac-dev" }, { "binary_version": "1.3.0-1.1", "binary_name": "libguac19" } ] }
{ "binaries": [ { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "guacd" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac-client-rdp0t64" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac-client-ssh0t64" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac-client-telnet0t64" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac-client-vnc0t64" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac-dev" }, { "binary_version": "1.3.0-1.3ubuntu1", "binary_name": "libguac19t64" } ] }