CVE Vulnerabilities

CVE-2023-5240

Published: Oct 13, 2023 | Modified: Oct 17, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

Affected Software

Name Vendor Start Version End Version
Devolutions_server Devolutions * 2023.2.8.0 (including)

References