Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2022-0006

Multiple vulnerabilities were fixed in Devolutions Server 2022.2.

Affected Products

Devolutions Server
2022.1 and earlier

Change Log

Initial Publication - 2022-07-05

Low - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

HTML injection in the secure message title

Some HTML tags could be injected in the title of secure messages. Javascript code execution via this injection is not possible due to sanitizing done by the Angular framework. An attacker with access to Devolutions Server could use it to alter the rendering of the page or redirect a user to another site.

Affected Products

CVE(s)

CVE-2022-2316

Remediation and Workarounds

Upgrade to Devolutions Server 2022.2

High - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Incorrect handling of permissions when creating a user with a pre-existing username

When deleting a user, the permission assignments remained in the database. If a new user was created with the same username, the user would get the permissions of that previous user.

Starting with Devolutions Server 2022.2, permissions are assigned based on the user unique ID instead of its username.

Affected Products

CVE(s)

CVE-2022-33996

Remediation and Workarounds

Upgrade to Devolutions Server 2022.2

Devolutions Logo

Helping organizations control the IT chaos by providing highly-secure password, remote connection and privileged access management solutions.

DEVOLUTIONS

Legal & privacy | infos@devolutions.net

All rights reserved © 2025 Devolutions