Severity
Medium
Analysis Summary
CVE-2020-11997
Apache Guacamole could allow a remote authenticated attacker to obtain sensitive information, caused by inconsistent restriction of connection history. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain connection history information, and use this information to launch further attacks against the affected system.
Impact
Information disclosure
Affected Vendors
Apache
Affected Products
Apache Guacamole 1.2.0
Remediation
Upgrade to the latest version of Guacamole (1.3.0 or later)