CVE-2025-2278: Medium severity Devolutions Server vulnerability
Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2278?
CVE-2025-2278 is considered a high severity vulnerability due to improper access control allowing unauthorized information access.
How do I fix CVE-2025-2278?
To fix CVE-2025-2278, upgrade to Devolutions Server version 2024.3.14 or later.
Who is affected by CVE-2025-2278?
CVE-2025-2278 affects users of Devolutions Server versions up to 2024.3.13.
What kind of information can be accessed due to CVE-2025-2278?
CVE-2025-2278 allows authenticated users to access sensitive information about temporary access requests and checkout requests.
Is there a workaround for CVE-2025-2278?
There are no officially recommended workarounds for CVE-2025-2278; the best action is to apply the security update.