Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59v2-78g4-8w49

Опубликовано: 26 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy".

This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy".

This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

EPSS

Процентиль: 39%
0.00178
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.8
nvd
11 месяцев назад

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

EPSS

Процентиль: 39%
0.00178
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-285