MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2023-0010

Devolutions Server support ticket endpoints are affected by a security vulnerability.

Affected Products

Devolutions Server
2023.1.5.0 and below

Change Log

Initial publication - 2023-04-17 Fixed typo - 2023-04-24

Endpoint for diagnostic logs not limited to administrators

Medium 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.

CVE(s)

CVE-2023-2118

Remediation and Workarounds

Upgrade to Devolutions Server 2023.1.6.0 or higher

Credits

Jico