PT-2023-16816 · Devolutions · Devolutions Server
CVE-2023-1201
·
Publicado
2023-03-06
·
Atualizado
2023-03-15
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Server versions 2022.3.12 and below
Description
The issue concerns improper access control in the secure messages feature, allowing an authenticated attacker with the message UUID to access the contained data.
Recommendations
For Devolutions Server versions 2022.3.12 and below, consider restricting access to the secure messages feature until a fix is available. As a temporary workaround, limit the exposure of message UUIDs to minimize the risk of unauthorized access.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Devolutions Server