CVE-2018-1340

CVE-2018-1340

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user’s session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user’s session token if unencrypted HTTP requests are made to the same domain.

Source: CVE-2018-1340

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다