Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57674 | Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2023-0019/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2024-09-06T18:40:19.905Z
Reserved: 2023-10-03T13:22:28.118Z
Link: CVE-2023-5358
Updated: 2024-08-02T07:59:43.681Z
Status : Modified
Published: 2023-11-01T18:15:09.883
Modified: 2024-11-21T08:41:36.373
Link: CVE-2023-5358
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD