Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5256-r6g6-4j2j

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью

Описание

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-863

Связанные уязвимости

nvd
4 дня назад

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-863