VDB
CVE-2018-1340
CVE-2018-1340
PUBLISHED
CVSS 7.5 HIGH
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the same domain.
EPSS 2.13% · 80.5th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
2.13%
80.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | guacamole-client | 0.9.9+dfsg-1, 0 |
| Ubuntu:16.04:LTS | guacamole-client | 0, 0.8.3-1.1, 0.8.3-1.2 |
Timeline
- Jan 23, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-1340 third-party-advisory
- https://www.openwall.com/lists/oss-security/2019/01/24/2 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1340 third-party-advisory