Описание
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.1.20.0 (исключая)
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00184
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 5.3
github
около 2 месяцев назад
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
EPSS
Процентиль: 8%
0.00184
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-284