Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2023-0017
Devolutions Server is affected by a security vulnerability.
Affected Products
Change Log
2023-10-13 - Initial publication
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N 4.9 medium
Information leak in PAM propagation scripts
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
Affected Products
CVE(s)
CVE-2023-5240
Remediation and Workarounds
Upgrade to Devolutions Server 2023.2.9.0 or higher.

