Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Devolutions_server | Devolutions | * | 2023.2.8.0 (including) |