PT-2022-11969 · Apache+1 · Apache Guacamole+1

Finn Steglich

·

Published

2022-01-11

·

Updated

2025-01-29

·

CVE-2021-43999

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Guacamole versions 1.2.0 through 1.3.0
Description The issue concerns the improper validation of responses from a SAML identity provider. If SAML support is enabled, a malicious user may assume the identity of another Guacamole user.
Recommendations For Apache Guacamole versions 1.2.0 and 1.3.0, consider disabling SAML support until a patch is available. Restrict access to the SAML identity provider integration to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2853
ALT-PU-2023-1077
ALT-PU-2025-2021
BIT-GUACAMOLE-2021-43999
BIT-GUACAMOLE-SERVER-2021-43999
CVE-2021-43999

Affected Products

Alt Linux
Apache Guacamole