Devolutions

Devolutions Server

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 27.11.2025 15:30:47
  • Zuletzt bearbeitet 03.12.2025 14:46:33

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

  • EPSS 0.57%
  • Veröffentlicht 27.11.2025 15:30:30
  • Zuletzt bearbeitet 03.12.2025 14:54:08

SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.

  • EPSS 0.36%
  • Veröffentlicht 27.11.2025 15:30:13
  • Zuletzt bearbeitet 03.12.2025 14:47:18

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

  • EPSS 0.59%
  • Veröffentlicht 06.11.2025 16:37:14
  • Zuletzt bearbeitet 10.11.2025 16:31:06

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step...

  • EPSS 0.4%
  • Veröffentlicht 06.11.2025 16:36:14
  • Zuletzt bearbeitet 10.11.2025 16:30:59

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions...

  • EPSS 0.31%
  • Veröffentlicht 22.10.2025 17:15:56
  • Zuletzt bearbeitet 25.11.2025 18:15:49

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults an...

  • EPSS 0.42%
  • Veröffentlicht 22.10.2025 17:15:56
  • Zuletzt bearbeitet 25.11.2025 18:15:49

An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request.

  • EPSS 0.23%
  • Veröffentlicht 15.10.2025 19:45:10
  • Zuletzt bearbeitet 03.12.2025 14:51:58

Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.

  • EPSS 0.31%
  • Veröffentlicht 30.07.2025 16:10:05
  • Zuletzt bearbeitet 19.08.2025 13:15:41

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : ...

  • EPSS 0.4%
  • Veröffentlicht 30.07.2025 16:06:46
  • Zuletzt bearbeitet 06.08.2025 14:37:13

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during stand...