CVE-2018-1340: Missing Encryption of Sensitive Data
(updated )
Apache Guacamole uses a cookie for client-side storage of the user session token. This cookie lacks the secure
flag, which could allow an attacker to steal the user session token if unencrypted HTTP requests are made to the same domain.
References
Detect and mitigate CVE-2018-1340 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →