Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
{
"binaries": [
{
"binary_version": "0.8.3-2",
"binary_name": "guacd"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac-dev"
},
{
"binary_version": "0.8.3-2",
"binary_name": "libguac5"
}
]
}
{
"binaries": [
{
"binary_version": "0.9.9-2build1",
"binary_name": "guacd"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-telnet0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac-dev"
},
{
"binary_version": "0.9.9-2build1",
"binary_name": "libguac11"
}
]
}
{
"binaries": [
{
"binary_version": "1.3.0-1.1",
"binary_name": "guacd"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-rdp0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-ssh0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-telnet0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-client-vnc0"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac-dev"
},
{
"binary_version": "1.3.0-1.1",
"binary_name": "libguac19"
}
]
}
{
"binaries": [
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "guacd"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-rdp0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-ssh0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-telnet0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-client-vnc0t64"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac-dev"
},
{
"binary_version": "1.3.0-1.3ubuntu1",
"binary_name": "libguac19t64"
}
]
}