Security & Compliance

DEVO-2021-0002

Zusammenfassung

Multiple vulnerabilities were fixed in Devolutions Server 2020.3.

Betroffene Produkte

Devolutions Server 2020.2 and earlier

Änderungsprotokoll

Initial Publication - 2021-03-30

Schweregrad

High

Produkt

Devolutions Server

Behobene Version

2020.3

Broken Authentication with Windows domain users (CVE-2021-23923)

Beschreibung

Under specific conditions, domain users could authenticate as another user in Devolutions Server when the setting auto create domain users is enabled.

Authenticating as another user could provide access passwords that are normally only available to the other user, such as entries in the user private vault. This vulnerability can’t be used to authenticate to a specific user, the authenticated user is defined by a server side configuration.

Behebungen und Workarounds

Update to Devolutions 2020.3 or higher.

Schweregrad

High - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Betroffene Produkte

Devolutions Server 2020.2 and earlier

CVE(s)

CVE-2021-23923

Broken access control on Password List entry elements (CVE-2021-23921)

Beschreibung

Credentials stored in Password List entries do not apply correctly access control rules when used with Remote Desktop Manager.

Behebungen und Workarounds

Update to Devolutions Server 2020.3 or higher

Schweregrad

High - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Betroffene Produkte

Devolutions Server 2020.2 and earlier

CVE(s)

CVE-2021-23921

Exposure of sensitive information in diagnostic files (CVE-2021-23924)

Beschreibung

Sensitive information including passwords could be unintentionally included in diagnostic files that are used for troubleshooting.

Behebungen und Workarounds

Update to Devolutions Server 2020.3 or higher

Schweregrad

Medium - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Betroffene Produkte

Devolutions Server 2020.2 and earlier

CVE(s)

CVE-2021-23924

Stored cross-site scripting (XSS) vulnerability in URL for entries of type Document (CVE-2021-23925)

Beschreibung

The URLs for entries of type "Document" are not validated properly against javascript code execution.

Behebungen und Workarounds

Update to Devolutions Server 2020.3 or higher

Schweregrad

High - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Betroffene Produkte

Devolutions Server 2020.2 and earlier

CVE(s)

CVE-2021-23925

Wir helfen Unternehmen dabei, das IT-Chaos zu meistern, indem wir Lösungen für Passwortverwaltung, Remoteverbindungen und privilegierte Zugriffsverwaltung bereitstellen.

DEVOLUTIONS

Sicherheit & Datenschutz | infos@devolutions.net

Alle Rechte vorbehalten © 2025 Devolutions