Lucene search

K
nvd[email protected]NVD:CVE-2023-2445
HistoryMay 02, 2023 - 2:15 p.m.

CVE-2023-2445

2023-05-0214:15:09
web.nvd.nist.gov
2
improper access control
subscriptions folder
devolutions server
folder path filter
administrator privileges
usage information
user vaults
specific folder name

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

23.8%

Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.

Affected configurations

Nvd
Node
devolutionsdevolutions_serverRange<2023.1.3.0
VendorProductVersionCPE
devolutionsdevolutions_server*cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

23.8%

Related for NVD:CVE-2023-2445