Apache Guacamole是美国阿帕奇(Apache)基金会的一款无客户端的远程桌面网关。该产品支持VNC、RDP和SSH等协议。 Apache Guacamole 1.2.0 and earlier 存在安全漏洞,该漏洞源于如果多个用户共享对同一连接的访问权限,那么这些用户可能能够看到其他哪些用户访问了该连接,以及访问该连接的IP地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache Guacamole | Apache Guacamole 1.2.0 and older | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-28477 | 7.5 HIGH | Prototype Pollution |
| CVE-2020-28478 | 7.5 HIGH | Prototype Pollution |
| CVE-2020-28472 | 7.3 HIGH | Prototype Pollution |
| CVE-2020-28480 | 7.3 HIGH | Prototype Pollution |
| CVE-2020-28482 | 5.9 MEDIUM | Cross-site Request Forgery (CSRF) |
| CVE-2020-28479 | 5.9 MEDIUM | Denial of Service (DoS) |
| CVE-2020-28481 | 5.3 MEDIUM | Insecure Defaults |
| CVE-2020-8581 | Clustered Data ONTAP 安全漏洞 | |
| CVE-2021-22498 | Micro Focus Application Lifecycle Management 代码问题漏洞 | |
| CVE-2021-3184 | MISP 跨站脚本漏洞 | |
| CVE-2020-27270 | 多款Sooil产品授权问题漏洞 | |
| CVE-2020-27272 | 多款Sooil产品访问控制错误漏洞 | |
| CVE-2020-27276 | 多款Sooil产品授权问题漏洞 | |
| CVE-2021-20190 | FasterXML jackson-databind 代码问题漏洞 | |
| CVE-2021-3183 | File.com Fat Client 代码问题漏洞 | |
| CVE-2020-27256 | 多款Sooil产品信任管理问题漏洞 | |
| CVE-2020-27258 | 多款Sooil产品信息泄露漏洞 | |
| CVE-2020-27264 | 多款Sooil产品安全特征问题漏洞 | |
| CVE-2020-27266 | 多款Sooil产品授权问题漏洞 | |
| CVE-2020-27268 | 多款Sooil产品授权问题漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet