The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.
| Software | From | Fixed in |
|---|---|---|
| teradici / cloud_access_connector_legacy | - | 2020-04-20 |
| teradici / cloud_access_connector | - | 15.x |