CVE Vulnerabilities

CVE-2023-5358

Published: Nov 01, 2023 | Modified: Nov 09, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.

Affected Software

Name Vendor Start Version End Version
Devolutions_server Devolutions * 2023.3.4.0 (excluding)

References