MENU PRINCIPAL
Solutions

Packages

blue box

Full power for small teams

All products available in our Starter Pack at half price for teams of 5

Comparer toutes nos solutions

Vue d'ensemble rapide

Personalized trial for 100+ users

Free expert or self-guided proof of concept for up to 90 days

Seamless integrations with RDM

Browse our 100+ integrations and boost your productivity

Sécurité et conformité

Nous respectons les normes les plus élevées pour protéger vos données et garantir la confiance.

DEVO-2022-0006

Multiple vulnerabilities were fixed in Devolutions Server 2022.2.

Produits affectés

Devolutions Server
2022.1 and earlier

Journal des modifications

Initial Publication - 2022-07-05

Low - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

HTML injection in the secure message title

Some HTML tags could be injected in the title of secure messages. Javascript code execution via this injection is not possible due to sanitizing done by the Angular framework. An attacker with access to Devolutions Server could use it to alter the rendering of the page or redirect a user to another site.

Produits affectés

CVE(s)

CVE-2022-2316

Mesures correctives et solutions de contournement

Upgrade to Devolutions Server 2022.2

High - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Incorrect handling of permissions when creating a user with a pre-existing username

When deleting a user, the permission assignments remained in the database. If a new user was created with the same username, the user would get the permissions of that previous user.

Starting with Devolutions Server 2022.2, permissions are assigned based on the user unique ID instead of its username.

Produits affectés

CVE(s)

CVE-2022-33996

Mesures correctives et solutions de contournement

Upgrade to Devolutions Server 2022.2