CVE-2020-11997

MEDIUM

Apache Guacamole < 1.2.0 - Unauthorized Connection History Access

Title source: llm
STIX 2.1

Description

Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

Scores

CVSS v3 4.3
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-276
Status published
Products (1)
apache/guacamole < 1.2.0
Published Jan 19, 2021
Tracked Since Feb 18, 2026