CVE-2025-2278
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 862
Summary
CVE-2025-2278 is a vulnerability affecting Devolutions Server 2024.3.13 and earlier versions. An authenticated user can exploit improper access control in the temporary access requests and checkout requests endpoints. This issue grants the user unauthorized access to information about these requests through a known request ID. Successful exploitation of this vulnerability could lead to unintended data exposure, potentially resulting in privacy concerns or more severe consequences. It is recommended that users apply the available patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.