Sécurité et conformité
DEVO-2021-0002
Résumé
Multiple vulnerabilities were fixed in Devolutions Server 2020.3.
Produits affectés
Devolutions Server 2020.2 and earlier
Journal des modifications
Initial Publication - 2021-03-30
Sévérité
High
Produit
Devolutions Server
Version corrigée
2020.3
Broken Authentication with Windows domain users (CVE-2021-23923)
Description
Under specific conditions, domain users could authenticate as another user in Devolutions Server when the setting auto create domain users is enabled.
Authenticating as another user could provide access passwords that are normally only available to the other user, such as entries in the user private vault. This vulnerability can’t be used to authenticate to a specific user, the authenticated user is defined by a server side configuration.
Mesures correctives et solutions de contournement
Update to Devolutions 2020.3 or higher.
Sévérité
High - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Produits affectés
Devolutions Server 2020.2 and earlier
CVE(s)
CVE-2021-23923
Broken access control on Password List entry elements (CVE-2021-23921)
Description
Credentials stored in Password List entries do not apply correctly access control rules when used with Remote Desktop Manager.
Mesures correctives et solutions de contournement
Update to Devolutions Server 2020.3 or higher
Sévérité
High - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Produits affectés
Devolutions Server 2020.2 and earlier
CVE(s)
CVE-2021-23921
Exposure of sensitive information in diagnostic files (CVE-2021-23924)
Description
Sensitive information including passwords could be unintentionally included in diagnostic files that are used for troubleshooting.
Mesures correctives et solutions de contournement
Update to Devolutions Server 2020.3 or higher
Sévérité
Medium - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Produits affectés
Devolutions Server 2020.2 and earlier
CVE(s)
CVE-2021-23924
Stored cross-site scripting (XSS) vulnerability in URL for entries of type Document (CVE-2021-23925)
Description
The URLs for entries of type "Document" are not validated properly against javascript code execution.
Mesures correctives et solutions de contournement
Update to Devolutions Server 2020.3 or higher
Sévérité
High - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Produits affectés
Devolutions Server 2020.2 and earlier
CVE(s)
CVE-2021-23925