CVE-2025-8353: Medium severity Devolutions Server vulnerability
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8353?
CVE-2025-8353 is classified as a critical severity vulnerability due to the potential for unauthorized access to sensitive JIT Groups.
How do I fix CVE-2025-8353?
To fix CVE-2025-8353, you should upgrade Devolutions Server to version 2025.2.4.1 or later.
What systems are affected by CVE-2025-8353?
CVE-2025-8353 affects Devolutions Server versions up to and including 2025.2.4.0.
What type of vulnerability is CVE-2025-8353?
CVE-2025-8353 is a UI synchronization vulnerability that allows access to deleted JIT Groups.
Can CVE-2025-8353 be exploited remotely?
Yes, CVE-2025-8353 can be exploited remotely by an authenticated user.