Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2023-11-01T17:17:31.501Z

Updated: 2024-09-06T18:40:19.905Z

Reserved: 2023-10-03T13:22:28.118Z

Link: CVE-2023-5358

cve-icon Vulnrichment

Updated: 2024-08-02T07:59:43.681Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-01T18:15:09.883

Modified: 2023-11-09T17:40:10.643

Link: CVE-2023-5358

cve-icon Redhat

No data.