Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
2022-01-11T22:15:07.627
2024-11-21T06:30:10.790
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | guacamole | 1.2.0 | Yes |
Application | apache | guacamole | 1.3.0 | Yes |