Uploaded image for project: 'Guacamole'
  1. Guacamole
  2. GUACAMOLE-1775

Auth token as a parameter in "session/tunnels/<tunnel ID>/protocol" request

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Trivial
    • Resolution: Fixed
    • 1.4.0, 1.5.0
    • 1.5.2
    • guacamole, guacamole-client
    • None

    Description

      The following HTTP requests example generated by Guacamole client contains authentication service tokens via URL query parameters, which could be leaked from server log files, “Referer header” of HTTP request, etc. 

      Example: GET /api/session/tunnels/<tunnel ID>/protocol?token=<token>

       

      This has been found in 1.4.0 and 1.5.0. 

       

      Attachments

        Issue Links

          Activity

            People

              mjumper Mike Jumper
              aresli Ares
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 2h
                  2h
                  Remaining:
                  Remaining Estimate - 2h
                  2h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified