Security & Compliance

DEVO-2023-0014

Summary

Devolutions Server is affected by a security vulnerability.

Affected Products

Devolutions Server 2023.1.8 and earlier

Change Log

Initial publication - 2023-06-20

Severity

Medium

Product

Devolutions Server

Fix Version

2023.2

Improper deletion of resource in the user management feature

Description

Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access.

Remediation and Workarounds

Upgrade to Devolutions Server 2023.2.1 and higher

Severity

Medium - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N 4.2

Affected Products

Devolutions Server 2023.1.8 and earlier

CVE(s)

CVE-2023-2400