Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mpq-hm4j-g84v

Опубликовано: 01 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

EPSS

Процентиль: 11%
0.00036
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.4
nvd
7 дней назад

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

EPSS

Процентиль: 11%
0.00036
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287