Apache Guacamole
cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*
- >= 0.8.0, <= 1.5.5
A vulnerability exists in the terminal emulator of Apache Guacamole in versions through 1.5.5. The issue arises because the application fails to properly validate console codes received from servers over text-based protocols such as SSH. This flaw could enable a malicious user with access to a text-based connection to execute arbitrary code with the privileges of the guacd process, by sending a specially-crafted sequence of console codes.
Exploitation of this vulnerability could lead to arbitrary code execution on the server, with the same privileges as the guacd process.
Users are advised to upgrade to Apache Guacamole version 1.6.0 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.