PT-2023-16816 · Devolutions · Devolutions Server

CVE-2023-1201

·

Publicado

2023-03-06

·

Atualizado

2023-03-15

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2022.3.12 and below
Description The issue concerns improper access control in the secure messages feature, allowing an authenticated attacker with the message UUID to access the contained data.
Recommendations For Devolutions Server versions 2022.3.12 and below, consider restricting access to the secure messages feature until a fix is available. As a temporary workaround, limit the exposure of message UUIDs to minimize the risk of unauthorized access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-1201

Produtos afetados

Devolutions Server