Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2023-0010
Devolutions Server support ticket endpoints are affected by a security vulnerability.
Affected Products
Change Log
Initial publication - 2023-04-17 Fixed typo - 2023-04-24
Endpoint for diagnostic logs not limited to administrators
Medium 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.
CVE(s)
CVE-2023-2118
Remediation and Workarounds
Upgrade to Devolutions Server 2023.1.6.0 or higher
Credits
Jico