Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2023-0005 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2023-03-06T17:15:00.735Z
Updated: 2024-08-02T05:40:59.782Z
Reserved: 2023-03-06T15:51:14.721Z
Link: CVE-2023-1201
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-10T21:15:14.627
Modified: 2024-11-21T07:38:39.553
Link: CVE-2023-1201
Redhat
No data.