CVE-2023-1603
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Permission bypass when importing or synchronizing entries in User vault
in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Affected (1)
Products: Devolutions: Devolutions Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2023.1.3.0 |
References (2)
Source: security@devolutions.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.