Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hf9-2h6f-g638

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server.

This issue affects :

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0
  • Devolutions Server 2025.3.20.0 and earlier

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server.

This issue affects :

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0
  • Devolutions Server 2025.3.20.0 and earlier

EPSS

Процентиль: 16%
0.00247
Низкий

7.1 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

EPSS

Процентиль: 16%
0.00247
Низкий

7.1 High

CVSS3

Дефекты

CWE-918