CVE-2025-12808 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting…
Medium CVSS: 6.5

CVE-2025-12808

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.





This issue affects the following versions :

* Devolutions Server 2025.3.2.0 through 2025.3.5.0
*

Devolutions Server 2025.2.15.0 and earlier
Vendor
Devolutions
Product
Devolutions Server
CWE
CWE-284
Yayın Tarihi
2025-11-06 17:15:42
Güncelleme
2025-11-10 16:30:59
Source Identifier
security@devolutions.net
KEV Date Added
-

Kategoriler

Referanslar