MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2023-0013

Devolutions Server subscription functionality is affected by a security vulnerability

Affected Products

Devolutions Server
2023.1.1.0 and below

Change Log

Initial publication - 2023-05-02

Improper access control in Subscriptions Folder path filter

Low - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.

CVE(s)

CVE-2023-2445

Remediation and Workarounds

Upgrade to Devolutions Server to 2023.1.3 and higher