Security & Compliance

DEVO-2023-0018

Summary

Devolutions Server is affected by a security vulnerability.

Affected Products

Devolutions Server 2022.3.13.0 and earlier

Change Log

2023-10-16 - Initial publication

Severity

Medium

Product

Devolutions Server

Fix Version

2023.1

Issue in permission inheritance

Description

Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.

Remediation and Workarounds

Upgrade to Devolutions Server 2023.1 and higher

Severity

Medium 6.8 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

Devolutions Server 2022.3.13.0 and earlier

CVE(s)

CVE-2023-5575