Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.
History

Wed, 02 Jul 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions devolutions Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Vendors & Products Devolutions
Devolutions devolutions Server

Thu, 05 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Jun 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.
Weaknesses CWE-284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2025-06-05T13:41:42.695Z

Updated: 2025-06-05T14:06:43.685Z

Reserved: 2025-01-23T20:14:30.466Z

Link: CVE-2025-0691

cve-icon Vulnrichment

Updated: 2025-06-05T14:06:13.634Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-05T14:15:30.987

Modified: 2025-07-02T13:11:13.287

Link: CVE-2025-0691

cve-icon Redhat

No data.