linuxserver / gclient

NodeJS application replacement for the default Guacamole Client
GNU General Public License v3.0
69 stars 20 forks source link

Update guacamole-lite to 07.0 #13

Closed rwd5213 closed 2 years ago

rwd5213 commented 2 years ago

bump guacamole-lite to version 0.7.0. This is to fix a critical vulnerability in 0.6.3. Version 0.6.3 depends on version 0.4.2 of deep-extend that contains the vulnerability CVE-2018-3750.

Lightly tested in rebuilding a fedora rdesktop-web and then a fedora webtop using that as the base. So far things seem fine.

thelamer commented 2 years ago

Just a heads up I am not ignoring this it is just that this breaks audio which is why it is currently pinned.

thelamer commented 2 years ago

Ref https://github.com/linuxserver/gclient/issues/14