CVE-2023-0952

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:02

Type Values Removed Values Added
Summary Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization. Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.

10 Mar 2023, 14:18

Type Values Removed Values Added
First Time Devolutions
Devolutions devolutions Server
CWE CWE-863
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://devolutions.net/security/advisories/DEVO-2023-0003 - (MISC) https://devolutions.net/security/advisories/DEVO-2023-0003 - Vendor Advisory

01 Mar 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-01 08:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-0952

Mitre link : CVE-2023-0952

CVE.ORG link : CVE-2023-0952


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-863

Incorrect Authorization