First published: Wed Apr 14 2021(Updated: )
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Devolutions Devolutions Server | <2020.3.18 | |
Devolutions Devolutions Server | <2021.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28048.
The title of this vulnerability is 'An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18'.
The severity of CVE-2021-28048 is medium with a CVSS score of 6.5.
Devolutions Server versions before 2021.1 and Devolutions Server LTS before 2020.3.18 are affected by this vulnerability.
A remote attacker can exploit this vulnerability to leak cross-origin data via a crafted HTML page.