Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrg4-m5xw-9pq5

Опубликовано: 01 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.

This issue affects Server: from 2026.1.6 through 2026.1.11.

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.

This issue affects Server: from 2026.1.6 through 2026.1.11.

EPSS

Процентиль: 11%
0.00036
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 6.5
nvd
7 дней назад

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

EPSS

Процентиль: 11%
0.00036
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201