MENU PRINCIPAL
Solutions

Packages

blue box

Full power for small teams

All products available in our Starter Pack at half price for teams of 5

Comparer toutes nos solutions

Vue d'ensemble rapide

Personalized trial for 100+ users

Free expert or self-guided proof of concept for up to 90 days

Seamless integrations with RDM

Browse our 100+ integrations and boost your productivity

Sécurité et conformité

Nous respectons les normes les plus élevées pour protéger vos données et garantir la confiance.

DEVO-2021-0005

A vulnerability was fixed were private key were returned unencrypted by the connections/partial endpoint.

Produits affectés

Devolutions Server
2021.1.17 and earlier.
2020.3.20 (LTS) and earlier.

Journal des modifications

Initial Publication - 2021-06-30 Added CVE - 2021-07-13

Low - CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Private key returned unencrypted in connections/partial endpoint (CVE-2021-36382)

Private keys are returned by the connections/partial endpoint without being encrypted. This could lead to data exposure for installations that do not have TLS enabled.

Produits affectés

CVE(s)

CVE-2021-36382

Mesures correctives et solutions de contournement

Update to Devolutions Server 2021.1.18 or higher.
Update to Devolutions Server LTS 2020.3.21 or higher.

This issue is completely mitigated when Devolutions Server is configured to use TLS. The confidentiality of private keys can also be protected by setting a strong password on them.