Security & Compliance
DEVO-2023-0018
Summary
Devolutions Server is affected by a security vulnerability.
Affected Products
Devolutions Server 2022.3.13.0 and earlier
Change Log
2023-10-16 - Initial publication
Severity
Medium
Product
Devolutions Server
Fix Version
2023.1
Issue in permission inheritance
Description
Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.
Remediation and Workarounds
Upgrade to Devolutions Server 2023.1 and higher
Severity
Medium 6.8 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
Devolutions Server 2022.3.13.0 and earlier
CVE(s)
CVE-2023-5575