Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52vv-5wf4-fghj

Опубликовано: 04 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

EPSS

Процентиль: 6%
0.00023
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-841

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

EPSS

Процентиль: 6%
0.00023
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-841