Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfw6-c783-wrw2

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью

Описание

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-284

Связанные уязвимости

nvd
4 дня назад

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-284