Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://devolutions.net/security/advisories/DEVO-2023-0013/ | vendor advisory |