Security & Compliance
DEVO-2023-0008
Zusammenfassung
Devolutions Server and Remote Desktop Manager are affected by multiple security vulnerabilities.
Betroffene Produkte
Remote Desktop Manager 2023.1.9 and belowDevolutions Server 2022.3.13 and below
Änderungsprotokoll
Initial Publication - 2023-03-23
Schweregrad
High
Produkt
Remote Desktop Manager, Devolutions Server
Behobene Version
RDM 2023.1.10, DVLS 2023.1.0
Permission bypass when importing or synchronizing entries (CVE-2023-1202)
Beschreibung
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Behebungen und Workarounds
Update to Remote Desktop Manager 2023.1.10 or higher
Schweregrad
High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)
Betroffene Produkte
Remote Desktop Managers 2023.1.9 and earlier
CVE(s)
CVE-2023-1202
Permission bypass when importing or synchronizing entries (CVE-2023-1603)
Beschreibung
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Behebungen und Workarounds
Update to Devolutions Server 2023.1.3.0 or higher
Schweregrad
High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)
Betroffene Produkte
Devolutions Server 2022.3.13 and earlier
CVE(s)
CVE-2023-1603