#VU86013 Input validation error in Guacamole - CVE-2023-30575
Published: February 1, 2024
Guacamole
Apache Foundation
Description
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake. A remote user can pass specially crafted input to the application and inject Guacamole instructions during the handshake.