Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2023-0005 |
|
History
Thu, 06 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2023-03-06T17:15:00.735Z
Updated: 2025-03-06T14:53:59.575Z
Reserved: 2023-03-06T15:51:14.721Z
Link: CVE-2023-1201
Updated: 2024-08-02T05:40:59.782Z
Status : Modified
Published: 2023-03-10T21:15:14.627
Modified: 2024-11-21T07:38:39.553
Link: CVE-2023-1201
No data.