Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2023-11-01T17:17:31.501Z

Updated: 2023-11-01T17:18:14.337Z

Reserved: 2023-10-03T13:22:28.118Z


Link: CVE-2023-5358

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-01T18:15:09.883

Modified: 2023-11-09T17:40:10.643


Link: CVE-2023-5358

JSON object: View

cve-icon Redhat Information

No data.