Improper access control in permissions component in...
Moderate severity
Unreviewed
Published
Jun 5, 2025
to the GitHub Advisory Database
•
Updated Jun 5, 2025
Description
Published by the National Vulnerability Database
Jun 5, 2025
Published to the GitHub Advisory Database
Jun 5, 2025
Last updated
Jun 5, 2025
Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.
References