Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2019-01-23T00:00:00

Updated: 2019-02-09T10:57:01

Reserved: 2017-12-07T00:00:00


Link: CVE-2018-1340

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-02-07T22:29:00.287

Modified: 2023-11-07T02:55:59.530


Link: CVE-2018-1340

JSON object: View

cve-icon Redhat Information

No data.

CWE